[Bug 1232776] New: AUDIT-1: supergfxctl: review of D-Bus service supergfxd.service
https://bugzilla.suse.com/show_bug.cgi?id=1232776 Bug ID: 1232776 Summary: AUDIT-1: supergfxctl: review of D-Bus service supergfxd.service Classification: openSUSE Product: openSUSE Tumbleweed Version: Current Hardware: Other OS: openSUSE Tumbleweed Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: security-team@suse.de Reporter: R_Nik_C@proton.me QA Contact: security-team@suse.de Target Milestone: --- Found By: --- Blocker: --- For my package found in OBS in hardware:supergfxctl I would like a whitelisting for the following rpmlint error: <relevant output from build log>
supergfxctl.x86_64: E: dbus-file-unauthorized (Badness: 10000) /etc/dbus-1/system.d/org.supergfxctl.Daemon.conf (sha256 file digest default filter:144bf742215f74f9d7da0876430e3942241d6df3a27bf4cf9945a461d905ce85 shell filter:144bf742215f74f9d7da0876430e3942241d6df3a27bf4cf9945a461d905ce85 xml filter:feeda577d27ded2d0d252d626bfc897a687d81aa1ee0f334cfb997151e40969b)
P.S. I just wanted to submit new package in factory sr#1221280 and this is required for next steps. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1232776 R N <R_Nik_C@proton.me> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |R_Nik_C@proton.me -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1232776 https://bugzilla.suse.com/show_bug.cgi?id=1232776#c1 --- Comment #1 from R N <R_Nik_C@proton.me> --- Submit request number changed to sr#1221300 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1232776 R N <R_Nik_C@proton.me> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |luke@ljones.dev -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1232776 https://bugzilla.suse.com/show_bug.cgi?id=1232776#c8 --- Comment #8 from R N <R_Nik_C@proton.me> --- (In reply to Matthias Gerstner from comment #7)
I will try to fix everything to an acceptable state as soon as I can. Thank you very much. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1232776 https://bugzilla.suse.com/show_bug.cgi?id=1232776#c10 --- Comment #10 from R N <R_Nik_C@proton.me> --- (In reply to Matthias Gerstner from comment #9)
Good, take your time, just ping the bug when you have something new.
Hello, As the author of the code itself said, he doesn't have time for this project now (obviously to rewrite it in "polkit") I made some changes as a patch as you may see everything here. https://build.opensuse.org/package/show/home:RN:branches:hardware/supergfxct... I hope after such changes everything is acceptable. But I have one more question please, maybe using the "video" group would be a better idea then separated "supergfxctl"? -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1232776 https://bugzilla.suse.com/show_bug.cgi?id=1232776#c11 --- Comment #11 from R N <R_Nik_C@proton.me> --- Or maybe "hardware" group? (it contains "video" and also "render" group) -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1232776 https://bugzilla.suse.com/show_bug.cgi?id=1232776#c13 --- Comment #13 from R N <R_Nik_C@proton.me> --- (In reply to Matthias Gerstner from comment #12)
All right then, I have done some little changes. Added "video" group and separated "supergfxctl" group. I just supposed it will not gonna be issue at all. So everything you may check here. https://build.opensuse.org/package/show/home:RN:branches:hardware/supergfxct... I hope that everything is as it should be, please take a look at it. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1232776 https://bugzilla.suse.com/show_bug.cgi?id=1232776#c15 --- Comment #15 from R N <R_Nik_C@proton.me> --- (In reply to Matthias Gerstner from comment #14)
All right, looks good to me, thanks. Can you submit it to the devel project? Then I'll start the whitelisting process.
Done. Thank you very much. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1232776 https://bugzilla.suse.com/show_bug.cgi?id=1232776#c17 --- Comment #17 from OBSbugzilla Bot <bwiedemann+obsbugzillabot@suse.com> --- This is an autogenerated message for OBS integration: This bug (1232776) was mentioned in https://build.opensuse.org/request/show/1225050 Factory / rpmlint -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1232776 R N <R_Nik_C@proton.me> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |R_Nik_C@proton.me -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1232776 https://bugzilla.suse.com/show_bug.cgi?id=1232776#c1 --- Comment #1 from R N <R_Nik_C@proton.me> --- Submit request number changed to sr#1221300 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1232776 R N <R_Nik_C@proton.me> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |luke@ljones.dev -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1232776 https://bugzilla.suse.com/show_bug.cgi?id=1232776#c8 --- Comment #8 from R N <R_Nik_C@proton.me> --- (In reply to Matthias Gerstner from comment #7)
I will try to fix everything to an acceptable state as soon as I can. Thank you very much. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1232776 https://bugzilla.suse.com/show_bug.cgi?id=1232776#c10 --- Comment #10 from R N <R_Nik_C@proton.me> --- (In reply to Matthias Gerstner from comment #9)
Good, take your time, just ping the bug when you have something new.
Hello, As the author of the code itself said, he doesn't have time for this project now (obviously to rewrite it in "polkit") I made some changes as a patch as you may see everything here. https://build.opensuse.org/package/show/home:RN:branches:hardware/supergfxct... I hope after such changes everything is acceptable. But I have one more question please, maybe using the "video" group would be a better idea then separated "supergfxctl"? -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1232776 https://bugzilla.suse.com/show_bug.cgi?id=1232776#c11 --- Comment #11 from R N <R_Nik_C@proton.me> --- Or maybe "hardware" group? (it contains "video" and also "render" group) -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com