Created attachment 360340 [details] Patch to drop capabilities Description of problem: As part of the lowering capabilities project, we should drop all unnecessary capabilities in all daemons.
For this patch to work, you need to BuildRequires: libcap-ng-devel and autoreconfig also needs to be run since this changes configure.ac.
Hi Steve, Thanks for the patch. I imagine this is something we'd want to apply upstream right? Would you mind filing a bug here: https://bugs.freedesktop.org/enter_bug.cgi?product=ConsoleKit Thanks.
Turns out there is problem with this patch. ConsoleKit seems to need CAP_DAC_OVERRIDE in addition to what's already given. Seems to be related to /dev/tty, but not 100% sure. If ConsoleKit does need DAC_OVERRIDE, then there is no possibility of confining this app.
ConsoleKit is not confinable in its current implementation.