Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Maybe I'm missing something, but why not simply `setcap cap_wake_alarm+p gnome-clocks` and any other app that may legitimately use this?


No, you're not missing anything. I should've been clearer that I was talking about gnome-clocks specifically, which wants to use systemd both so that only systemd needs the privileges rather than gnome-clocks itself and so that it can autostart gnome-clocks using the timer [1] even if gnome-clocks is down at the time (ie gnome-clocks doesn't itself need to keep the timerfd alive).

In general, setcap'ing the binary will work fine.

[1]: https://gitlab.gnome.org/GNOME/gnome-clocks/-/merge_requests...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: