Bug ID | 971580 |
---|---|
Summary | polkit-default-privs.standard is too restrictive for FirewallD |
Classification | openSUSE |
Product | openSUSE Tumbleweed |
Version | 2015* |
Hardware | Other |
OS | Other |
Status | NEW |
Severity | Normal |
Priority | P5 - None |
Component | Security |
Assignee | security-team@suse.de |
Reporter | mchandras@suse.com |
QA Contact | qa-bugs@suse.de |
Found By | --- |
Blocker | --- |
Hi, commit 930ad4431ef640a38523e26ff29918ba14089d23 [1] overrides the FirewallD polkit actions but the .standard variant is similar to .restrictive so FirewallD is locked down even on normal desktop operation. In my opinion this is probably a mistake. Would you consider mirroring the .standard file to the /usr/share/polkit-1/actions/org.fedoraproject.FirewallD1.desktop.policy as provided by firewalld? I can submit a PR myself but I would like to know why this decision was made (in bnc#907625) before I create one. [1] https://github.com/openSUSE/polkit-default-privs/commit/930ad4431ef640a38523e26ff29918ba14089d23