Skip to content

Comment on Removal of Deepin Desktop from OpenSUSE Due to Packaging Policy Violationparent

Comments

A Linux distribution is free to define its own security policy, which serves as a common understanding between developers and users.

And not all packages require auditing. The primary concern here lies with D-Bus services. Many D-Bus services need to run as root while allowing non-root users to access them. This enables users to perform tasks such as mounting or unmounting block devices without relying on SUID or sudo.

Such services are often referred to as "security boundaries", because they help isolate different privilege levels. Thus, security of those service is vital, especially in enterprise-oriented distributions.

The package showed a big license agreement and implemented circumvention steps! We're a bit beyond the D-Bus auditing issues.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.