3 ms·
Ironically, polkit is designed to avoid the need to have suid binaries, since it allows other programs to obtain restricted privileges without full suid. The pr
by matthewbauer 5y ago
Ironically, polkit is designed to avoid the need to have suid binaries, since it allows other programs to obtain restricted privileges without full suid. The problem is, polkit itself still needs suid to hand out privileges to other programs.
- Spivak 5y agoYes and no, applications integrated with Polkit need to have privileges (usually by running as root). Polkit itself doesn't need any privileges since it's just a framework for programs that have elevated privileges to ask if a user is allowed to use them. pkexec a program bundled with but not really part of Polkit is suid as the method it uses to gain elevated privileges rather than running a daemon.