Bug ID 1209921
Summary AUDIT-0: mozillavpn: review of polkit and d-bus files
Classification openSUSE
Product openSUSE Tumbleweed
Version Current
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee security-team@suse.de
Reporter me@cimba.li
QA Contact security-team@suse.de
Found By ---
Blocker ---

I���������m trying to package Mozilla VPN cleanly to request inclusion in the
network:vpn project.

The package is currently found in OBS in home:cimbali:mozillavpn, and I would
like to request a whitelisting for the following rpmlint errors:

[  940s] mozillavpn.x86_64: E: polkit-untracked-privilege (Badness: 10)
org.mozilla.vpn.activate (no:no:auth_admin)
[  940s] mozillavpn.x86_64: E: polkit-untracked-privilege (Badness: 10)
org.mozilla.vpn.deactivate (no:no:auth_admin)

and:

[  940s] mozillavpn.x86_64: E: dbus-file-unauthorized (Badness: 10)
/usr/share/dbus-1/system.d/org.mozilla.vpn.conf (sha256 file digest default
filter:e74ba6daec764d45a243a9e23d1740ec8e9ded2d355bc9ac471964cfc4a6f862 shell
filter:3776b809929e0b7fa2edb9163e274ff4c0c04326cc67fae61831d2e01f21bfd4 xml
filter:98e9c1413257012deb4f2eedfd107a83497fe143250f70086755b79041208743)

[  940s] mozillavpn.x86_64: E: dbus-file-unauthorized (Badness: 10)
/usr/share/dbus-1/system-services/org.mozilla.vpn.dbus.service (sha256 file
digest default
filter:70eee51675c8fd78189ee97a473ce6612a06af56297fcec8b8d0c76c930d0a81 shell
filter:70eee51675c8fd78189ee97a473ce6612a06af56297fcec8b8d0c76c930d0a81 xml
filter:<failed-to-calculate>)

The various upstream source files are:
https://github.com/mozilla-mobile/mozilla-vpn-client/blob/main/src/apps/vpn/platforms/linux/daemon/org.mozilla.vpn.policy
https://github.com/mozilla-mobile/mozilla-vpn-client/blob/main/src/apps/vpn/platforms/linux/daemon/org.mozilla.vpn.conf
https://github.com/mozilla-mobile/mozilla-vpn-client/blob/main/src/apps/vpn/platforms/linux/daemon/org.mozilla.vpn.dbus.service

---

Finally this file is installed as a systemd service, but it is not enabled by
default:

https://github.com/mozilla-mobile/mozilla-vpn-client/blob/main/linux/mozillavpn.service.in


You are receiving this mail because: