Created attachment 360340 [details]
Patch to drop capabilities
Description of problem:
As part of the lowering capabilities project, we should drop all unnecessary
capabilities in all daemons.
For this patch to work, you need to BuildRequires: libcap-ng-devel and autoreconfig also needs to be run since this changes configure.ac.
Thanks for the patch. I imagine this is something we'd want to apply upstream right? Would you mind filing a bug here:
Turns out there is problem with this patch. ConsoleKit seems to need CAP_DAC_OVERRIDE in addition to what's already given. Seems to be related to /dev/tty, but not 100% sure. If ConsoleKit does need DAC_OVERRIDE, then there is no possibility of confining this app.
ConsoleKit is not confinable in its current implementation.