[Bug 1206756] New: AUDIT-WHITELIST: NetworkManager-iodine: move dbus system.d file to /usr
https://bugzilla.suse.com/show_bug.cgi?id=1206756 Bug ID: 1206756 Summary: AUDIT-WHITELIST: NetworkManager-iodine: move dbus system.d file to /usr Classification: openSUSE Product: openSUSE Tumbleweed Version: Current Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: security-team@suse.de Reporter: gmbr3@opensuse.org QA Contact: qa-bugs@suse.de Found By: --- Blocker: --- Move /etc/dbus-1/system.d/nm-iodine-service.conf to /usr/share/dbus-1/system.d/nm-iodine-service.conf -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1206756 https://bugzilla.suse.com/show_bug.cgi?id=1206756#c1 --- Comment #1 from Callum Farmer <gmbr3@opensuse.org> --- https://build.opensuse.org/request/show/1045903 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1206756 https://bugzilla.suse.com/show_bug.cgi?id=1206756#c2 Matthias Gerstner <matthias.gerstner@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |security-team@suse.de --- Comment #2 from Matthias Gerstner <matthias.gerstner@suse.com> --- This was reviewed ages ago in bug 781071. Having a quick look at the current situation of the service as part of the path move might be a good idea. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1206756 Wolfgang Frisch <wolfgang.frisch@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |CONFIRMED CC| |matthias.gerstner@suse.com, | |wolfgang.frisch@suse.com Assignee|security-team@suse.de |wolfgang.frisch@suse.com -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1206756 https://bugzilla.suse.com/show_bug.cgi?id=1206756#c3 Wolfgang Frisch <wolfgang.frisch@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|CONFIRMED |IN_PROGRESS --- Comment #3 from Wolfgang Frisch <wolfgang.frisch@suse.com> --- I will be working on this. Upstream: https://honk.sigxcpu.org/piki/projects/network-manager-iodine/ https://gitlab.gnome.org/GNOME/network-manager-iodine openSUSE Factory packages: https://build.opensuse.org/package/show/openSUSE:Factory/iodine https://build.opensuse.org/package/show/openSUSE:Factory/NetworkManager-iodi... -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1206756 https://bugzilla.suse.com/show_bug.cgi?id=1206756#c4 --- Comment #4 from Wolfgang Frisch <wolfgang.frisch@suse.com> --- This package integrates the `iodine` IPv4-over-DNS client with NetworkManager. It is comprised of two parts, a GTK UI and a D-Bus service. Both are only accessible with root credentials. The D-Bus service `nm-iodine-service` runs under a separate system user account (`nm-iodine`) without any special privileges, no shell and no home directory. The service itself is written in glib-style C, of decent quality, in less than 1 kLOC. It interacts with the iodine binary, executing it asynchronously and parsing its output. Subprocess execution is performed with a proper argv-array. Its output is parsed with low level string manipulation with sufficient checks and range-checked glib functions. All good, as far as I can see. The underlying `iodine` package might be a different matter but that's outside the scope of this review. I will proceed with the whitelisting. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1206756 https://bugzilla.suse.com/show_bug.cgi?id=1206756#c12 Wolfgang Frisch <wolfgang.frisch@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|IN_PROGRESS |RESOLVED Resolution|--- |FIXED --- Comment #12 from Wolfgang Frisch <wolfgang.frisch@suse.com> --- The whitelisting has finally arrived in Factory. Closing. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com