about summary refs log tree commit diff
path: root/src/nm-helpers/README.md
diff options
context:
space:
mode:
authorMichael Biebl <biebl@debian.org>2025-12-13 13:49:03 +0100
committerMichael Biebl <biebl@debian.org>2025-12-13 13:49:03 +0100
commitb5001976dbff19f014171eed4a482e28ae7ec0f5 (patch)
tree64fbd4ff0dd3c92b6e78fa4172c9f57a2b20e1fa /src/nm-helpers/README.md
parentdef61b130ab011561ed66a1638a41d59c23b4710 (diff)
parent6de29285e533f4fec22a219013f3687edb6b7399 (diff)
Update upstream source from tag 'upstream/1.54.3'
Update to upstream version '1.54.3'
with Debian dir 29de9f9896550eb82236dfd0adfd428a49c51043
Diffstat (limited to 'src/nm-helpers/README.md')
-rw-r--r--src/nm-helpers/README.md51
1 files changed, 51 insertions, 0 deletions
diff --git a/src/nm-helpers/README.md b/src/nm-helpers/README.md
new file mode 100644
index 00000000..66a94292
--- /dev/null
+++ b/src/nm-helpers/README.md
@@ -0,0 +1,51 @@
+nm-helpers
+==========
+
+This directory contains stand-alone helper programs used by various
+components.
+
+nm-daemon-helper
+----------------
+
+A internal helper application that is spawned by NetworkManager to
+perform certain actions which can't be done in the daemon. 
+
+Currently it's used to do a reverse DNS lookup after reconfiguring the
+libc resolver (which is a process-wide operation), and to read files
+on behalf of unprivileged users (which requires a seteuid that affects
+all the threads of the process).
+
+This is not directly useful to the user.
+
+nm-libnm-helper
+---------------
+
+A internal helper application that is spawned by libnm to perform
+certain actions without impacting the calling process.
+
+This is not directly useful to the user.
+
+nm-priv-helper
+--------------
+
+This is a D-Bus activatable, exit-on-idle service, which
+provides an internal API to NetworkManager daemon.
+
+This has no purpose for the user, it is an implementation detail
+of the daemon.
+
+The purpose is that `nm-priv-helper` can execute certain
+privileged operations which NetworkManager process is not
+allowed to. We want to sandbox NetworkManager as much as
+possible, and nm-priv-helper provides a controlled way to
+perform some very specific operations.
+
+As such, nm-priv-helper should still be sandboxed too to only
+being able to execute the operations that are necessary for
+NetworkManager.
+
+nm-priv-helper will reject all D-Bus requests that are not
+originating from the current name owner of
+"org.freedesktop.NetworkManager".  That is, it is supposed to
+only reply to NetworkManager daemon and as such is not useful to
+the user directly.