4 ms·
Without looking at the he specific implementation There should be a service running as uid=0 that exposes an unprivileged API. This service then takes the RPC
by ongy 2y ago
Without looking at the he specific implementation
There should be a service running as uid=0 that exposes an unprivileged API.
This service then takes the RPC and does authorization with polkit.
I.e. the unprivileged part doesn't talk to polkit directly. But a privileged part uses polkit instead of a custom sudoers style config.