Add XorgNoNewPrivileges configuration option
This allows Linux's no_new_privs restriction to be disabled when starting the X server, which may be desirable if xrdp is running inside a kernel confinement framework such as AppArmor or SELinux.
This commit is contained in:
@@ -39,6 +39,11 @@ RestrictOutboundClipboard=none
|
||||
RestrictInboundClipboard=none
|
||||
; Set to 'no' to prevent users from logging in with alternate shells
|
||||
#AllowAlternateShell=true
|
||||
; On Linux systems, the Xorg X11 server is normally invoked using
|
||||
; no_new_privs to avoid problems if the executable is suid. This may,
|
||||
; however, interfere with the use of security modules such as AppArmor.
|
||||
; Leave this unset unless you need to disable it.
|
||||
#XorgNoNewPrivileges=true
|
||||
|
||||
[Sessions]
|
||||
;; X11DisplayOffset - x11 display number offset
|
||||
|
||||
Reference in New Issue
Block a user