Mailinglist Archive: opensuse-commit (1029 mails)

< Previous Next >
commit polkit-default-privs for openSUSE:Factory

Hello community,

here is the log from the commit of package polkit-default-privs for
openSUSE:Factory
checked in at Wed Jul 27 16:18:33 CEST 2011.



--------
--- polkit-default-privs/polkit-default-privs.changes 2011-07-21
09:15:25.000000000 +0200
+++
/mounts/work_src_done/STABLE/polkit-default-privs/polkit-default-privs.changes
2011-07-27 15:16:58.000000000 +0200
@@ -1,0 +2,6 @@
+Wed Jul 27 13:16:37 UTC 2011 - lnussel@xxxxxxx
+
+- change inactive backlight helper privileges to 'no' (bnc#708639)
+- remove hal privileges
+
+-------------------------------------------------------------------

calling whatdependson for head-i586


++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ polkit-default-privs.spec ++++++
--- /var/tmp/diff_new_pack.gIS7lK/_old 2011-07-27 16:17:24.000000000 +0200
+++ /var/tmp/diff_new_pack.gIS7lK/_new 2011-07-27 16:17:24.000000000 +0200
@@ -23,7 +23,7 @@
License: GPLv2+
Group: Productivity/Security
Version: 12.1
-Release: 1
+Release: 2
Summary: SUSE PolicyKit default permissions
Source: polkit-default-privs-%version.tar.bz2
BuildRoot: %{_tmppath}/%{name}-%{version}-build

++++++ polkit-default-privs-12.1.tar.bz2 ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/polkit-default-privs-12.1/polkit-default-privs.restrictive
new/polkit-default-privs-12.1/polkit-default-privs.restrictive
--- old/polkit-default-privs-12.1/polkit-default-privs.restrictive
2011-07-21 09:14:12.000000000 +0200
+++ new/polkit-default-privs-12.1/polkit-default-privs.restrictive
2011-07-27 15:16:28.000000000 +0200
@@ -29,57 +29,6 @@
org.freedesktop.NetworkManager.settings.modify.system auth_admin
org.freedesktop.NetworkManager.settings.modify.hostname auth_admin
#
-org.freedesktop.hal.killswitch.bluetooth
auth_admin_keep_always
-org.freedesktop.hal.killswitch.wlan
auth_admin_keep_always
-org.freedesktop.hal.killswitch.wwan
auth_admin_keep_always
-org.freedesktop.hal.lock
auth_admin_keep_always
-org.freedesktop.hal.storage.mount-fixed
auth_admin_keep_always
-org.freedesktop.hal.storage.mount-removable
auth_admin_keep_always
-org.freedesktop.hal.storage.unmount-others
auth_admin_keep_always
-org.freedesktop.hal.storage.eject
auth_admin_keep_always
-org.freedesktop.hal.storage.crypto-setup-fixed
auth_admin_keep_always
-org.freedesktop.hal.storage.crypto-setup-removable
auth_admin_keep_always
-org.freedesktop.hal.wol.enabled
auth_admin_keep_always
-org.freedesktop.hal.wol.enable
auth_admin_keep_always
-org.freedesktop.hal.wol.supported
auth_admin_keep_always
-# shutdown/reboot should be consistent with consolekit
-org.freedesktop.hal.power-management.shutdown
auth_admin_keep_always
-org.freedesktop.hal.power-management.shutdown-multiple-sessions
auth_admin
-org.freedesktop.hal.power-management.reboot
auth_admin_keep_always
-org.freedesktop.hal.power-management.reboot-multiple-sessions auth_admin
-org.freedesktop.hal.power-management.set-powersave
auth_admin_keep_always
-org.freedesktop.hal.power-management.suspend
auth_admin_keep_always
-org.freedesktop.hal.power-management.hibernate
auth_admin_keep_always
-org.freedesktop.hal.power-management.standby
auth_admin_keep_always
-org.freedesktop.hal.power-management.cpufreq
auth_admin_keep_always
-org.freedesktop.hal.power-management.lcd-panel
auth_admin_keep_always
-org.freedesktop.hal.power-management.light-sensor
auth_admin_keep_always
-org.freedesktop.hal.power-management.keyboard-backlight
auth_admin_keep_always
-org.freedesktop.hal.dockstation.undock
auth_admin_keep_always
-org.freedesktop.hal.leds.brightness
auth_admin_keep_always
-#
-# device access
-#
-org.freedesktop.hal.device-access.sound
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.video4linux
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.cdrom
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.dvb
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.camera
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.scanner
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.audio-player
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.ieee1394-iidc
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.ieee1394-avc
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.pda
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.floppy
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.modem
auth_admin_keep_always
-org.freedesktop.hal.device-access.joystick
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.mouse
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.video
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.fingerprint-reader
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.obex
auth_admin_keep_always
-org.freedesktop.hal.device-access.ppdev
auth_admin_keep_always
-org.freedesktop.hal.device-access.removable-block
auth_admin_keep_always
-#
org.libvirt.unix.monitor
auth_admin_keep_always
org.libvirt.unix.manage
auth_admin_keep_always
#
@@ -136,7 +85,7 @@
org.gnome.policykit.examples.kick-bar no:no:auth_self
org.gnome.policykit.examples.kick-baz no:no:auth_self
#
-# should be consistent with hal
+# should be consistent with udisks
org.freedesktop.consolekit.system.stop
auth_admin_keep_always
org.freedesktop.consolekit.system.stop-multiple-users
auth_admin_keep_always
org.freedesktop.consolekit.system.restart
auth_admin_keep_always
@@ -186,7 +135,7 @@
org.freedesktop.policykit.example.pkexec.run-frobnicate auth_admin

#
-# device-kit. Should be consitent with hal
+# device-kit. Should be consitent with consolekit
#
org.freedesktop.udisks.filesystem-mount auth_admin
org.freedesktop.udisks.filesystem-mount-system-internal auth_admin
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/polkit-default-privs-12.1/polkit-default-privs.standard
new/polkit-default-privs-12.1/polkit-default-privs.standard
--- old/polkit-default-privs-12.1/polkit-default-privs.standard 2011-07-21
09:14:12.000000000 +0200
+++ new/polkit-default-privs-12.1/polkit-default-privs.standard 2011-07-27
15:16:28.000000000 +0200
@@ -29,64 +29,6 @@
org.freedesktop.NetworkManager.settings.modify.system auth_admin
org.freedesktop.NetworkManager.settings.modify.hostname auth_admin
#
-org.freedesktop.hal.killswitch.bluetooth
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.killswitch.wlan
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.killswitch.wwan
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.lock
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.storage.mount-fixed
auth_admin_keep_always
-org.freedesktop.hal.storage.mount-removable
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.storage.unmount-others
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.storage.eject
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.storage.crypto-setup-fixed
auth_admin_keep_always
-org.freedesktop.hal.storage.crypto-setup-removable
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.wol.enabled
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.wol.enable
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.wol.supported
auth_admin_keep_always:auth_admin_keep_always:yes
-# shutdown/reboot should be consistent with consolekit
-org.freedesktop.hal.power-management.shutdown
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.power-management.shutdown-multiple-sessions
auth_admin:auth_admin:yes
-org.freedesktop.hal.power-management.reboot
auth_admin:auth_admin:yes
-org.freedesktop.hal.power-management.reboot-multiple-sessions
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.power-management.set-powersave
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.power-management.suspend
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.power-management.hibernate
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.power-management.standby
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.power-management.cpufreq
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.power-management.lcd-panel
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.power-management.light-sensor
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.power-management.keyboard-backlight
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.dockstation.undock
auth_admin_keep_always:auth_admin_keep_always:yes
-org.freedesktop.hal.leds.brightness
auth_admin_keep_always:auth_admin_keep_always:yes
-#
-# device access
-#
-# we allow device access for both active and inactive sessions.
-# Revoking device ACLs for inactive sessions would have no effect on
-# already open file descriptors anyways. With a revoke system call
-# it would be possible but would also mean that e.g. a sound playing
-# appliction would have to be killed or would forcefully stop
-# playing sound which is not what we want.
-#
-org.freedesktop.hal.device-access.sound
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.video4linux
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.cdrom
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.dvb
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.camera
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.scanner
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.audio-player
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.ieee1394-iidc
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.ieee1394-avc
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.pda
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.floppy
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.modem
auth_admin_keep_always
-org.freedesktop.hal.device-access.joystick
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.mouse
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.video
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.fingerprint-reader
auth_admin_keep_always:yes:yes
-org.freedesktop.hal.device-access.obex
auth_admin_keep_always
-org.freedesktop.hal.device-access.ppdev
auth_admin_keep_always
-org.freedesktop.hal.device-access.removable-block
auth_admin_keep_always
-#
org.libvirt.unix.monitor yes
org.libvirt.unix.manage
auth_admin_keep_always
#
@@ -143,7 +85,7 @@
org.gnome.policykit.examples.kick-bar no:no:auth_self
org.gnome.policykit.examples.kick-baz no:no:auth_self
#
-# should be consistent with hal
+# should be consistent with udisks
org.freedesktop.consolekit.system.stop
auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.consolekit.system.stop-multiple-users
auth_admin:auth_admin:yes
org.freedesktop.consolekit.system.restart
auth_admin:auth_admin:yes
@@ -193,7 +135,7 @@
org.freedesktop.policykit.example.pkexec.run-frobnicate
auth_admin:auth_admin:auth_admin

#
-# device-kit. Should be consitent with hal
+# device-kit. Should be consitent with consolekit
#
org.freedesktop.udisks.filesystem-mount
auth_admin:auth_admin:yes
org.freedesktop.udisks.filesystem-mount-system-internal
auth_admin:auth_admin:auth_admin_keep
@@ -311,8 +253,8 @@
org.kde.kcontrol.kcmkdm.managethemes auth_admin_keep
org.kde.kcontrol.kcmkdm.save auth_admin
# kde backlight helper (bnc#672145)
-org.kde.powerdevil.backlighthelper.brightness
auth_admin:auth_admin:yes
-org.kde.powerdevil.backlighthelper.setbrightness
auth_admin:auth_admin:yes
+org.kde.powerdevil.backlighthelper.brightness no:no:yes
+org.kde.powerdevil.backlighthelper.setbrightness no:no:yes

# moblin

@@ -338,10 +280,10 @@
org.gnome.randr.install-system-wide auth_admin

# gnome-power-manager (bnc#650401)
-org.gnome.power.backlight-helper
auth_admin:auth_admin:yes
+org.gnome.power.backlight-helper no:no:yes
# xfce4-power-manager, bnc#665169
# code is copy&paste from gnome-power-manager
-org.xfce.power.backlight-helper
auth_admin:auth_admin:yes
+org.xfce.power.backlight-helper no:no:yes

# hp-drive-guard
com.hp.driveguard.toggle auth_admin


++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++



Remember to have fun...

--
To unsubscribe, e-mail: opensuse-commit+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse-commit+help@xxxxxxxxxxxx

< Previous Next >