[Bug 781569] New: security review: gnome-applets for GNOME 3.6
https://bugzilla.novell.com/show_bug.cgi?id=781569 https://bugzilla.novell.com/show_bug.cgi?id=781569#c0 Summary: security review: gnome-applets for GNOME 3.6 Classification: openSUSE Product: openSUSE Factory Version: 12.3 Milestone 0 Platform: Other OS/Version: Other Status: NEW Severity: Normal Priority: P5 - None Component: GNOME AssignedTo: security-team@suse.de ReportedBy: dimstar@opensuse.org QAContact: qa-bugs@suse.de Found By: --- Blocker: --- Based on a request from bug 780104, I enabled the cpufreq-selector applet / tool. This installs a system wide dbus service and is controlled by polkit. In order for the package to be able to enter Factory, this requires a security review and approval of the dbus / polkit rules. The current build fails with: [ 500s] (none): E: badness 20000 exceeds threshold 1000, aborting. [ 500s] gnome-applets.x86_64: E: suse-dbus-unauthorized-service (Badness: 10000) /usr/share/dbus-1/system-services/org.gnome.CPUFreqSelector.service [ 500s] gnome-applets.x86_64: E: suse-dbus-unauthorized-service (Badness: 10000) /etc/dbus-1/system.d/org.gnome.CPUFreqSelector.conf [ 500s] The package installs a DBUS system service file. If the package is intended [ 500s] for inclusion in any SUSE product please open a bug report to request review [ 500s] of the service by the security team. [ 500s] [ 500s] gnome-applets.x86_64: I: polkit-untracked-privilege org.gnome.cpufreqselector (??:no:auth_admin_keep) [ 500s] The privilege is not listed in /etc/polkit-default-privs.* which makes it [ 500s] harder for admins to find. If the package is intended for inclusion in any [ 500s] SUSE product please open a bug report to request review of the package by the [ 500s] security team -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=781569 https://bugzilla.novell.com/show_bug.cgi?id=781569#c Dominique Leuenberger <dimstar@opensuse.org> changed: What |Removed |Added ---------------------------------------------------------------------------- Blocks| |780104 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=781569 https://bugzilla.novell.com/show_bug.cgi?id=781569#c1 Marcus Meissner <meissner@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |meissner@suse.com Summary|security review: |AUDIT-0: gnome-applets for |gnome-applets for GNOME 3.6 |GNOME 3.6 --- Comment #1 from Marcus Meissner <meissner@suse.com> 2012-10-23 09:36:31 UTC --- Question is still open if GNOME should be able to do that or if it should be kept at kernel level. (basically a distribution integrator decision) -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=781569 https://bugzilla.novell.com/show_bug.cgi?id=781569#c3 Dominique Leuenberger <dimstar@opensuse.org> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution| |WONTFIX --- Comment #3 from Dominique Leuenberger <dimstar@opensuse.org> 2012-11-12 09:25:40 UTC --- Considering the gnome-applets is supposed to die out in gnome 3.8, investing any effort in this is a waste of time... -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com