13 ms·
Why does pipewire depend on it? Otherwise I'd just remove it right now.
by foxfluff 5y ago
Why does pipewire depend on it? Otherwise I'd just remove it right now.
- throwaway984393 5y agoSigh... Because systemd, dbus, polkit, pulseaudio, rtkit, etc are invasive weeds. Apps now depend on them exclusively so often that you have to provide some shim to replace their ABI if you don't want to use those components. I can't remember the specifics but pipewire probably only casually references it as part of a compatibility layer. In Alpine I'm pretty sure you can run pipewire without polkit but I'd have to check.
- throwawaysysd 5y agoOr it could be because those libraries actually do something and users want them? I really don't get these complaints. Is the C library an "invasive weed" because C programs require an ABI compatible C library to run?
- foxfluff 5y agoThey are invasive if they somehow end up on your system even if you don't need them and didn't ask for it. The C library is something that I actually need, unlike a GUI sudo prompt for.. audio? I don't even know what such a prompt looks like because I've never seen one.
- throwawaysysd 5y agoI'm sorry, now I really don't understand. If these libraries shipped with your distro, you asked for them. If they were dependencies of a package you installed, you asked for them. It's bizarre to me that there are hundreds of Linux distros with every combination of packages you could possibly ask for and I still see this complaints. It's very likely you didn't see a prompt because your distro configured it to not require a password. If you want to configure it to require a password, the system lets you do that. This is just another choice you have.
- foxfluff 5y agoNo, I didn't ask for a fucking GUI sudo with xml and javascript and local privilege escalation to root. I asked my computer to do something as basic as play sound, something that worked for decades without GUI sudo. Developers said they want to use pulseaudio for that. Whatever, if it finally plays audio without breaking every week. I don't have time to vet every package in every distro, and I didn't know it depends on a GUI sudo. > If these libraries shipped with your distro, you asked for them. If a bomb ships with a package you ordered, you asked for it. Or maybe not? Maybe I didn't ask for it but a bunch of devs decided that (quoting you) "the users all want" it and I wasn't there to keep tabs on them. And now that I know better, yes, I am looking for alternative distros because the ones I've been using include too many things I didn't ask for.
- throwawaysysd 5y ago>I asked my computer to do something as basic as play sound, something that worked for decades without GUI sudo Sure, security also was not great for decades. I know what you mean you don't have time to vet packages, very few people have time to do that, that's usually why you'd trust a vendor to do it for you and not keep second guessing their decisions because they published and fixed a CVE. >I am looking for alternative distros because the ones I've been using include too many things I didn't ask for. That's great, I wish you luck. Just keep in mind, eventually if you find you want to put a security prompt on something for whatever reason (maybe you find yourself shipping something to a less technically inclined user), I expect you will circle back around to the same solutions. They're there for you to use them. At that point it becomes whether the frustration with XML and Javascript is worth rewriting it with a different configuration format and scripting language. Maybe you also want to take these tools written in C and rewrite it in Go or Rust or something, I don't know. I would not say it's worth it unless you have some really extreme requirements. This doesn't to have the most expressive DSL you can think of it, it just needs to encode some simple logic in a well-understood way.
- foxfluff 5y ago> that's usually why you'd trust a vendor to do it for you and not keep second guessing their decisions because they published and fixed a CVE. Yes, I'm inevitably putting some trust in vendors. Unfortunately I'm having a hard time finding vendors (especially Linux vendors) that I can trust to make decisions that I find sensible and more or less in line with my intended usage of the system. I have some experience with OpenBSD (after using it for more than a decade on a server and a few years on a laptop), and I can say with reasonable confidence that they would have never allowed polkit to be a part of their system in the first place. Similar to how they eventually said no to kerberos and just purged it. Similar to how they've refused things like PAM. Similar to how audio kept working fine with sndio (a very simple library & daemon) while I constantly had to battle the overcomplicated audio subsystem and ever-churning daemons on Linux.. That's the kind of Linux vendor I would like: a vendor who's trying to build something simple, and not something that tries to be maximally flexible and "everything for everyone". A vendor who can make decisions and if needed, build their own thing that suits their goals instead of shipping the same things every other distro ships. There certainly are hundreds of distros as you say, but most of them offer little more than a different coat of paint, and ship the same third-party packages with more or less the same dependencies as you would have on any other Linux distro. After you've installed the few things you need, it doesn't matter much whether the banner says Arch, Fedora, Ubuntu, or whatever (in fact I run all three right now). > That's great, I wish you luck. Thank you.
- jcelerier 5y agoI'd guess it's because pipewire needs to access real-time capabilities of the kernel to enable low-latency audio, and those are only accessible as root sadly AFAIK (thus polkit, because pipewire does not run as root so there has to be something to grant the capacity to pw)
- mhitza 5y agoA bunch of things on a modern desktop linux system depend on it. Disregard what the user you replied to said, as polkit is a system to delegate elevated permission grants from GUI applications. A GUI sudo if you will, with XML and javascript code for its configuration files. I'm not near my computer, but I would guess pipewire (as it usually runs within the users session) might rely on it to access the sound hardware without needing to run as root. But just guessing.
- foxfluff 5y agoThe only things on my system that depend on it are pipewire and xorg-x11-drv-intel (which I don't need). It doesn't sound like you should need a GUI sudo with XML and Javascript for audio..
- 0xbadcafebee 5y agoIt does appear to exist solely to let users use their own local hardware: https://wiki.debian.org/PolicyKit https://wiki.debian.org/PolicyKit PolicyKit is an application-level toolkit for defining and handling the policy that allows unprivileged processes to speak to privileged processes, in order to grant some user the right to perform some tasks in some situations. It is sometimes referred to as "the sudo of systemd". Sample uses: Let the user Hibernate and shutdown the computer. Let the user manage (Wireless) connections. Let the user mount/eject a removable media (CD/DVD, USB keys...) Let the user access devices, like audio, scanner, etc. We already had a solution for this before: you add the user to the 'audio' group. And SELinux could do this too. But apparently RedHat just wanted another layer (https://lwn.net/Articles/258592/ https://lwn.net/Articles/258592/). "This is better than groups and setgid processes, because it means someone can't log in over ssh and mess with another user at the console." - Because that's what desktop users are really concerned about. We need more complexity because somebody might hax0r my desktop over SSH. And, wow, they really actually did use XML as their configuration: <match action="org.freedesktop.hal.storage.mount-fixed"> <match user="davidz"> <return result="yes"/> </match> <match user="freddy"> <return result="no"/> </match> </match> So, not only is it superfluous, it also doesn't make the user's life easier, it's super annoying to configure, everything depends on it, and now the thing intended to improve security has caused a security issue.
- hsbauauvhabzb 5y agoRemoving it won’t have a huge amount of value unless you give untrusted people shell access to your system - if your personal user is compromised they will have pretty much obtained the Crown Jewels anyway. Where this exploit is valuable to hackers is situations like escalating from the www user or similar.