Hello community,
here is the log from the commit of package polkit-default-privs for
openSUSE:Factory checked in at 2018-03-19 23:30:10
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/polkit-default-privs (Old)
and /work/SRC/openSUSE:Factory/.polkit-default-privs.new (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "polkit-default-privs"
Mon Mar 19 23:30:10 2018 rev:140 rq:585867 version:13.2
Changes:
--------
---
/work/SRC/openSUSE:Factory/polkit-default-privs/polkit-default-privs.changes
2018-02-05 10:50:00.292748562 +0100
+++
/work/SRC/openSUSE:Factory/.polkit-default-privs.new/polkit-default-privs.changes
2018-03-19 23:30:10.691102088 +0100
@@ -1,0 +2,26 @@
+Mon Mar 12 11:08:50 UTC 2018 - [email protected]
+
+- polkit-default-privs: mass amnesty whitelisting of untracked privileges. See
+ https://lists.opensuse.org/opensuse-factory/2018-02/msg01044.html for
+ rationale. This allows existing packages in Factory to continue building
+ after the tighter rpmlint-Factory checks become effective. Following
+ packages are affected:
+
+ - blueman (bsc#1083066)
+ - cinnamon settings-daemon (bnc#1083067)
+ - connman (bsc#1083069)
+ - flatpak (bsc#984817)
+ - fwupd (bsc#1083022)
+ - gsmartcontrol (bsc#1084693)
+ - gvfs (bsc#1073214)
+ - laptop-mode-tools (bsc#1084695)
+ - mate-system-monitor (bsc#1084701)
+ - nemo (bsc#1084702)
+ - nemo-extensions (bsc#1084703)
+ - PackageKit (bnc#993505)
+ - pantheon-files (bsc#1084704)
+ - scap-workbench (bsc#1084706)
+ - spice-gtk (bsc#1083025)
+ - sysprof (bsc#1083055)
+
+-------------------------------------------------------------------
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ polkit-default-privs-13.2.tar.bz2 ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/polkit-default-privs-13.2/polkit-default-privs.restrictive
new/polkit-default-privs-13.2/polkit-default-privs.restrictive
--- old/polkit-default-privs-13.2/polkit-default-privs.restrictive
2018-01-31 15:04:49.000000000 +0100
+++ new/polkit-default-privs-13.2/polkit-default-privs.restrictive
2018-03-12 12:18:55.000000000 +0100
@@ -401,6 +401,9 @@
org.cinnamon.settings-daemon.plugins.power.backlight-helper no:no:yes
org.cinnamon.settingsdaemon.datetimemechanism.configure
no:no:auth_admin_keep
+# cinnamon settings-daemon (bsc#1083067)
+org.cinnamon.settings-users auth_admin
+
# hp-drive-guard
com.hp.driveguard.toggle auth_admin
@@ -461,6 +464,9 @@
org.freedesktop.packagekit.package-reinstall
auth_admin:auth_admin:auth_admin_keep
org.freedesktop.packagekit.package-downgrade
auth_admin:auth_admin:auth_admin_keep
+# PackageKit (bnc#993505)
+org.freedesktop.packagekit.trigger-offline-upgrade
no:auth_admin:auth_admin
+
#
# gparted (bnc#810888)
#
@@ -727,6 +733,9 @@
# sysprof (bsc#996111)
org.gnome.sysprof2.perf-event-open auth_admin_keep
+# sysprof (bsc#1083055)
+org.gnome.sysprof2.get-kernel-symbols auth_admin_keep
+
# flatpak (bsc#984817)
org.freedesktop.Flatpak.app-install
auth_admin:auth_admin:auth_admin_keep
org.freedesktop.Flatpak.runtime-install
auth_admin:auth_admin:auth_admin_keep
@@ -737,6 +746,7 @@
org.freedesktop.Flatpak.app-update
auth_admin:auth_admin:auth_admin_keep
org.freedesktop.Flatpak.runtime-update
auth_admin:auth_admin:auth_admin_keep
org.freedesktop.Flatpak.appstream-update
auth_admin:auth_admin:auth_admin_keep
+org.freedesktop.Flatpak.configure
auth_admin:auth_admin:auth_admin_keep
# flatpak (bsc#1012961, bsc#1064011)
org.freedesktop.Flatpak.update-remote
auth_admin:auth_admin:auth_admin_keep
@@ -749,6 +759,9 @@
org.blueman.pppd.pppconnect auth_admin_keep
org.blueman.rfkill.setstate auth_admin_keep
+# blueman (bsc#1083066)
+org.blueman.bluez.config no:no:auth_admin_keep
+
# tuned (bsc#1007279)
com.redhat.tuned.gui.run auth_admin
com.redhat.tuned.active_profile yes
@@ -775,6 +788,9 @@
org.freedesktop.fwupd.update-internal-trusted auth_admin:no:auth_admin_keep
org.freedesktop.fwupd.update-hotplug-trusted auth_admin:no:auth_admin_keep
+# fwupd (bsc#1083022)
+org.freedesktop.fwupd.modify-remote auth_admin:no:auth_admin_keep
+
# deja-dup (bsc#1058935)
org.gnome.DejaDup.duplicity no:no:auth_admin
@@ -782,4 +798,38 @@
net.connman.modify auth_admin_keep
net.connman.vpn.modify auth_admin_keep
+# connman (bsc#1083069)
+net.connman.secret no:no:auth_admin_keep
+net.connman.vpn.secret no:no:auth_admin_keep
+
+# gsmartcontrol (bsc#1084693)
+org.gsmartcontrol auth_admin
+
+# gvfs (bsc#1073214)
+org.gtk.vfs.file-operations no:no:auth_admin_keep
+org.gtk.vfs.file-operations-helper no:no:auth_admin_keep
+
+# laptop-mode-tools (bsc#1084695)
+org.linux.lmt.gui.policy auth_admin
+
+# mate-system-monitor (bsc#1084701)
+org.mate.mate-system-monitor.kill no:no:auth_admin
+org.mate.mate-system-monitor.renice no:no:auth_admin
+
+# nemo (bsc#1084702)
+org.nemo.root no:no:auth_admin_keep
+
+# nemo-extensions (bsc#1084703)
+org.nemo-share.samba_install no:no:auth_admin_keep
+
+# pantheon-files (bsc#1084704)
+org.freedesktop.policykit.pkexec.pantheon-files
auth_admin:auth_admin:auth_admin
+org.freedesktop.policykit.pkexec.io.elementary.files
auth_admin:auth_admin:auth_admin
+
+# scap-workbench (bsc#1084706)
+scap-workbench-oscap.run auth_admin:auth_admin:auth_admin
+
+# spice-gtk (bsc#1083025)
+org.spice-space.lowlevelusbaccess no:no:auth_admin
+
###
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/polkit-default-privs-13.2/polkit-default-privs.standard
new/polkit-default-privs-13.2/polkit-default-privs.standard
--- old/polkit-default-privs-13.2/polkit-default-privs.standard 2018-01-31
15:04:49.000000000 +0100
+++ new/polkit-default-privs-13.2/polkit-default-privs.standard 2018-03-12
12:18:55.000000000 +0100
@@ -419,6 +419,9 @@
org.cinnamon.settings-daemon.plugins.power.backlight-helper no:no:yes
org.cinnamon.settingsdaemon.datetimemechanism.configure
no:no:auth_admin_keep
+# blueman (bsc#1083066)
+org.cinnamon.settings-users auth_admin
+
# hp-drive-guard
com.hp.driveguard.toggle auth_admin
com.hp.driveguard.install-setup auth_admin
@@ -477,6 +480,9 @@
org.freedesktop.packagekit.package-reinstall
auth_admin:auth_admin:auth_admin_keep
org.freedesktop.packagekit.package-downgrade
auth_admin:auth_admin:auth_admin_keep
+# PackageKit (bnc#993505)
+org.freedesktop.packagekit.trigger-offline-upgrade
auth_admin:auth_admin:auth_admin
+
#
# gparted (bnc#810888)
#
@@ -790,6 +796,9 @@
# sysprof (bsc#996111)
org.gnome.sysprof2.perf-event-open auth_admin_keep
+# sysprof (bsc#1083055)
+org.gnome.sysprof2.get-kernel-symbols auth_admin_keep
+
# flatpak (bsc#984817)
org.freedesktop.Flatpak.app-install
auth_admin:auth_admin:auth_admin_keep
org.freedesktop.Flatpak.runtime-install
auth_admin:auth_admin:auth_admin_keep
@@ -800,6 +809,7 @@
org.freedesktop.Flatpak.app-update
auth_admin:auth_admin:auth_admin_keep
org.freedesktop.Flatpak.runtime-update
auth_admin:auth_admin:auth_admin_keep
org.freedesktop.Flatpak.appstream-update
auth_admin:auth_admin:auth_admin_keep
+org.freedesktop.Flatpak.configure
auth_admin:auth_admin:auth_admin_keep
# flatpak (bsc#1012961, bsc#1064011)
org.freedesktop.Flatpak.update-remote auth_admin:auth_admin:yes
@@ -812,6 +822,9 @@
org.blueman.pppd.pppconnect auth_admin_keep
org.blueman.rfkill.setstate auth_admin_keep
+# blueman (bsc#1083066)
+org.blueman.bluez.config no:no:auth_admin_keep
+
# tuned (bsc#1007279)
com.redhat.tuned.gui.run auth_admin
com.redhat.tuned.active_profile yes
@@ -843,6 +856,9 @@
org.freedesktop.fwupd.update-internal-trusted auth_admin:no:yes
org.freedesktop.fwupd.update-hotplug-trusted auth_admin:no:yes
+# fwupd (bsc#1083022)
+org.freedesktop.fwupd.modify-remote auth_admin:no:auth_admin_keep
+
# deja-dup (bsc#1058935)
org.gnome.DejaDup.duplicity no:no:auth_admin
@@ -850,4 +866,38 @@
net.connman.modify auth_admin_keep
net.connman.vpn.modify auth_admin_keep
+# connman (bsc#1083069)
+net.connman.secret no:no:auth_admin_keep
+net.connman.vpn.secret no:no:auth_admin_keep_session
+
+# gsmartcontrol (bsc#1084693)
+org.gsmartcontrol auth_admin
+
+# gvfs (bsc#1073214)
+org.gtk.vfs.file-operations no:no:auth_admin_keep
+org.gtk.vfs.file-operations-helper no:no:auth_admin_keep
+
+# laptop-mode-tools (bsc#1084695)
+org.linux.lmt.gui.policy auth_admin
+
+# mate-system-monitor (bsc#1084701)
+org.mate.mate-system-monitor.kill no:no:auth_admin_keep
+org.mate.mate-system-monitor.renice no:no:auth_admin_keep
+
+# nemo (bsc#1084702)
+org.nemo.root no:no:auth_admin_keep
+
+# nemo-extensions (bsc#1084703)
+org.nemo-share.samba_install no:no:auth_admin_keep
+
+# pantheon-files (bsc#1084704)
+org.freedesktop.policykit.pkexec.pantheon-files
auth_admin:auth_admin:auth_admin
+org.freedesktop.policykit.pkexec.io.elementary.files
auth_admin:auth_admin:auth_admin
+
+# scap-workbench (bsc#1084706)
+scap-workbench-oscap.run
auth_admin_keep:auth_admin_keep:auth_admin_keep
+
+# spice-gtk (bsc#1083025)
+org.spice-space.lowlevelusbaccess auth_admin:no:auth_admin
+
###