about summary refs log tree commit diff
path: root/src/nm-priv-helper
diff options
context:
space:
mode:
Diffstat (limited to 'src/nm-priv-helper')
-rw-r--r--src/nm-priv-helper/README.md24
1 files changed, 24 insertions, 0 deletions
diff --git a/src/nm-priv-helper/README.md b/src/nm-priv-helper/README.md
new file mode 100644
index 00000000..576da7a7
--- /dev/null
+++ b/src/nm-priv-helper/README.md
@@ -0,0 +1,24 @@
+nm-priv-helper
+==============
+
+This is a D-Bus activatable, exit-on-idle service, which
+provides an internal API to NetworkManager daemon.
+
+This has no purpose for the user, it is an implementation detail
+of the daemon.
+
+The purpose is that `nm-priv-helper` can execute certain
+privileged operations which NetworkManager process is not
+allowed to. We want to sandbox NetworkManager as much as
+possible, and nm-priv-helper provides a controlled way to
+perform some very specific operations.
+
+As such, nm-priv-helper should still be sandboxed too to only
+being able to execute the operations that are necessary for
+NetworkManager.
+
+nm-priv-helper will reject all D-Bus requests that are not
+originating from the current name owner of
+"org.freedesktop.NetworkManager".  That is, it is supposed to
+only reply to NetworkManager daemon and as such is not useful to
+the user directly.