Hello community,
here is the log from the commit of package polkit-default-privs for
openSUSE:Factory checked in at 2018-07-12 09:17:42
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/polkit-default-privs (Old)
and /work/SRC/openSUSE:Factory/.polkit-default-privs.new (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "polkit-default-privs"
Thu Jul 12 09:17:42 2018 rev:146 rq:621429 version:13.2
Changes:
--------
---
/work/SRC/openSUSE:Factory/polkit-default-privs/polkit-default-privs.changes
2018-06-25 11:35:04.549703111 +0200
+++
/work/SRC/openSUSE:Factory/.polkit-default-privs.new/polkit-default-privs.changes
2018-07-12 09:17:43.542297583 +0200
@@ -1,0 +2,11 @@
+Fri Jul 6 15:58:13 UTC 2018 - [email protected]
+
+- polkit-default-privs: whitelist incremental libvirt actions (bnc#1100328)
+- polkit-default-privs: group together the large blocks of libvirt rules
+
+-------------------------------------------------------------------
+Thu Jul 5 12:42:45 UTC 2018 - [email protected]
+
+- polkit-default-privs: whitelist switchboard-plug-* (bsc#1088472)
+
+-------------------------------------------------------------------
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ polkit-default-privs-13.2.tar.bz2 ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/polkit-default-privs-13.2/polkit-default-privs.restrictive
new/polkit-default-privs-13.2/polkit-default-privs.restrictive
--- old/polkit-default-privs-13.2/polkit-default-privs.restrictive
2018-06-22 15:27:54.000000000 +0200
+++ new/polkit-default-privs-13.2/polkit-default-privs.restrictive
2018-07-06 17:56:05.000000000 +0200
@@ -38,10 +38,6 @@
org.freedesktop.NetworkManager.settings.modify.global-dns
auth_admin_keep:auth_admin_keep:auth_admin_keep
#
-#
-org.libvirt.unix.monitor
auth_admin_keep_always
-org.libvirt.unix.manage
auth_admin_keep_always
-#
# gnome-settings-daemon (bnc#690496)
#
org.gnome.settingsdaemon.datetimemechanism.configure auth_admin_keep
@@ -515,6 +511,11 @@
# powerdevil (bnc#825256)
org.kde.powerdevil.backlighthelper.syspath no:yes:yes
+#
+#
+org.libvirt.unix.monitor
auth_admin_keep_always
+org.libvirt.unix.manage
auth_admin_keep_always
+
# libvirt (bnc#827644) ( original wants yes:yes:yes)
org.libvirt.api.connect.getattr auth_admin_keep
org.libvirt.api.connect.read auth_admin_keep
@@ -541,98 +542,6 @@
org.libvirt.api.storage-vol.getattr auth_admin_keep
org.libvirt.api.storage-vol.read auth_admin_keep
-# MATE settings-daemon (bnc#831404)
-org.mate.settingsdaemon.datetimemechanism.settimezone auth_admin_keep
-org.mate.settingsdaemon.datetimemechanism.settime auth_admin_keep
-org.mate.settingsdaemon.datetimemechanism.configurehwclock auth_admin_keep
-org.mate.randr.install-system-wide auth_admin_keep
-org.mate.power.backlight-helper
auth_admin_keep:auth_admin_keep:yes
-
-# gufw
-com.ubuntu.pkexec.gufw auth_admin
-
-# policycoreutils (bnc#848550)
-org.selinux.restorecon auth_admin_keep
-org.selinux.setenforce auth_admin_keep
-org.selinux.semanage auth_admin_keep
-org.selinux.change_default_policy auth_admin_keep
-org.selinux.change_policy_type auth_admin_keep
-org.selinux.config.pkexec.run no:no:auth_admin
-org.selinux.relabel_on_boot auth_admin_keep
-
-# policycoreutils (bnc#878631)
-org.selinux.customized auth_admin_keep
-org.selinux.semodule_list auth_admin_keep
-
-# kwallet (bnc#849739)
-
-org.kde.kcontrol.kcmkwallet.save auth_admin_keep
-
-# kwallet5 (bnc#1033296)
-
-org.kde.kcontrol.kcmkwallet5.save auth_admin_keep
-
-# baloo (bnc#866131)
-org.kde.baloo.filewatch.raiselimit no:no:auth_admin_keep
-
-# pcsc-lite (bnc#864178)
-org.debian.pcsc-lite.access_pcsc no:no:yes
-org.debian.pcsc-lite.access_card no:no:yes
-
-# firewalld (bnc#907625)
-org.fedoraproject.FirewallD1.all auth_admin_keep
-org.fedoraproject.FirewallD1.info auth_admin_keep
-org.fedoraproject.FirewallD1.config auth_admin_keep
-org.fedoraproject.FirewallD1.config.info auth_admin_keep
-org.fedoraproject.FirewallD1.direct auth_admin_keep
-org.fedoraproject.FirewallD1.direct.info auth_admin_keep
-org.fedoraproject.FirewallD1.policies auth_admin_keep
-org.fedoraproject.FirewallD1.policies.info auth_admin_keep
-
-
-# KDE5 powerdevil (bnc#912121)
-org.kde.powerdevil.backlighthelper.brightnessvalue no:yes:yes
-org.kde.powerdevil.backlighthelper.brightnessvaluemax no:yes:yes
-org.kde.powerdevil.backlighthelper.setbrightnessvalue no:no:yes
-
-# powerdevil action-name changes (bnc#927275)
-org.kde.powerdevil.backlighthelper.brightness no:yes:yes
-org.kde.powerdevil.backlighthelper.brightnessmax no:yes:yes
-org.kde.powerdevil.backlighthelper.setbrightness no:no:yes
-
-
-# storaged (bnc#915770)
-com.redhat.lvm2.create-logical-volume auth_admin_keep
-com.redhat.lvm2.delete-logical-volume auth_admin_keep
-com.redhat.lvm2.rename-logical-volume auth_admin_keep
-com.redhat.lvm2.resize-logical-volume auth_admin_keep
-com.redhat.lvm2.activate-logical-volume auth_admin_keep
-com.redhat.lvm2.deactivate-logical-volume auth_admin_keep
-com.redhat.lvm2.snapshot-logical-volume auth_admin_keep
-com.redhat.lvm2.create-volume-group auth_admin_keep
-com.redhat.lvm2.delete-volume-group auth_admin_keep
-com.redhat.lvm2.rename-volume-group auth_admin_keep
-com.redhat.lvm2.manage-lvm auth_admin_keep
-
-# systemd new things in 218
-org.freedesktop.systemd1.manage-units
auth_admin:auth_admin:auth_admin_keep
-org.freedesktop.systemd1.manage-unit-files
auth_admin:auth_admin:auth_admin_keep
-org.freedesktop.systemd1.reload-daemon
auth_admin:auth_admin:auth_admin_keep
-
-# gnome-multi-writer (bnc#924062)
-org.gnome.MultiWriter.probe
auth_admin:auth_admin:auth_admin_keep
-
-# realmd (bnc#916767)
-org.freedesktop.realmd.configure-realm
auth_admin:auth_admin:auth_admin_keep
-org.freedesktop.realmd.deconfigure-realm
auth_admin:auth_admin:auth_admin_keep
-org.freedesktop.realmd.login-policy
auth_admin:auth_admin:auth_admin_keep
-# realmd (bsc#1048025)
-org.freedesktop.realmd.discover-realm
auth_admin:auth_admin:auth_admin_keep
-
-
-# netvisix (bsc#930195)
-org.opensuse.policykit.netvisix
auth_admin:auth_admin:auth_admin
-
# libvirt (bsc#959297)
org.libvirt.api.connect.detect-storage-pools auth_admin_keep
org.libvirt.api.connect.getattr auth_admin_keep
@@ -727,6 +636,105 @@
org.libvirt.api.storage-vol.read auth_admin_keep
org.libvirt.api.storage-vol.resize auth_admin_keep
+# libvirt (bsc#1100328)
+org.libvirt.api.connect.search-nwfilter-bindings auth_admin_keep
+org.libvirt.api.nwfilter.binding-getattr auth_admin_keep
+org.libvirt.api.nwfilter.binding-read auth_admin_keep
+org.libvirt.api.nwfilter.binding-create no
+org.libvirt.api.nwfilter.binding-delete no
+
+# MATE settings-daemon (bnc#831404)
+org.mate.settingsdaemon.datetimemechanism.settimezone auth_admin_keep
+org.mate.settingsdaemon.datetimemechanism.settime auth_admin_keep
+org.mate.settingsdaemon.datetimemechanism.configurehwclock auth_admin_keep
+org.mate.randr.install-system-wide auth_admin_keep
+org.mate.power.backlight-helper
auth_admin_keep:auth_admin_keep:yes
+
+# gufw
+com.ubuntu.pkexec.gufw auth_admin
+
+# policycoreutils (bnc#848550)
+org.selinux.restorecon auth_admin_keep
+org.selinux.setenforce auth_admin_keep
+org.selinux.semanage auth_admin_keep
+org.selinux.change_default_policy auth_admin_keep
+org.selinux.change_policy_type auth_admin_keep
+org.selinux.config.pkexec.run no:no:auth_admin
+org.selinux.relabel_on_boot auth_admin_keep
+
+# policycoreutils (bnc#878631)
+org.selinux.customized auth_admin_keep
+org.selinux.semodule_list auth_admin_keep
+
+# kwallet (bnc#849739)
+
+org.kde.kcontrol.kcmkwallet.save auth_admin_keep
+
+# kwallet5 (bnc#1033296)
+
+org.kde.kcontrol.kcmkwallet5.save auth_admin_keep
+
+# baloo (bnc#866131)
+org.kde.baloo.filewatch.raiselimit no:no:auth_admin_keep
+
+# pcsc-lite (bnc#864178)
+org.debian.pcsc-lite.access_pcsc no:no:yes
+org.debian.pcsc-lite.access_card no:no:yes
+
+# firewalld (bnc#907625)
+org.fedoraproject.FirewallD1.all auth_admin_keep
+org.fedoraproject.FirewallD1.info auth_admin_keep
+org.fedoraproject.FirewallD1.config auth_admin_keep
+org.fedoraproject.FirewallD1.config.info auth_admin_keep
+org.fedoraproject.FirewallD1.direct auth_admin_keep
+org.fedoraproject.FirewallD1.direct.info auth_admin_keep
+org.fedoraproject.FirewallD1.policies auth_admin_keep
+org.fedoraproject.FirewallD1.policies.info auth_admin_keep
+
+
+# KDE5 powerdevil (bnc#912121)
+org.kde.powerdevil.backlighthelper.brightnessvalue no:yes:yes
+org.kde.powerdevil.backlighthelper.brightnessvaluemax no:yes:yes
+org.kde.powerdevil.backlighthelper.setbrightnessvalue no:no:yes
+
+# powerdevil action-name changes (bnc#927275)
+org.kde.powerdevil.backlighthelper.brightness no:yes:yes
+org.kde.powerdevil.backlighthelper.brightnessmax no:yes:yes
+org.kde.powerdevil.backlighthelper.setbrightness no:no:yes
+
+
+# storaged (bnc#915770)
+com.redhat.lvm2.create-logical-volume auth_admin_keep
+com.redhat.lvm2.delete-logical-volume auth_admin_keep
+com.redhat.lvm2.rename-logical-volume auth_admin_keep
+com.redhat.lvm2.resize-logical-volume auth_admin_keep
+com.redhat.lvm2.activate-logical-volume auth_admin_keep
+com.redhat.lvm2.deactivate-logical-volume auth_admin_keep
+com.redhat.lvm2.snapshot-logical-volume auth_admin_keep
+com.redhat.lvm2.create-volume-group auth_admin_keep
+com.redhat.lvm2.delete-volume-group auth_admin_keep
+com.redhat.lvm2.rename-volume-group auth_admin_keep
+com.redhat.lvm2.manage-lvm auth_admin_keep
+
+# systemd new things in 218
+org.freedesktop.systemd1.manage-units
auth_admin:auth_admin:auth_admin_keep
+org.freedesktop.systemd1.manage-unit-files
auth_admin:auth_admin:auth_admin_keep
+org.freedesktop.systemd1.reload-daemon
auth_admin:auth_admin:auth_admin_keep
+
+# gnome-multi-writer (bnc#924062)
+org.gnome.MultiWriter.probe
auth_admin:auth_admin:auth_admin_keep
+
+# realmd (bnc#916767)
+org.freedesktop.realmd.configure-realm
auth_admin:auth_admin:auth_admin_keep
+org.freedesktop.realmd.deconfigure-realm
auth_admin:auth_admin:auth_admin_keep
+org.freedesktop.realmd.login-policy
auth_admin:auth_admin:auth_admin_keep
+# realmd (bsc#1048025)
+org.freedesktop.realmd.discover-realm
auth_admin:auth_admin:auth_admin_keep
+
+
+# netvisix (bsc#930195)
+org.opensuse.policykit.netvisix
auth_admin:auth_admin:auth_admin
+
# importd (bsc#964935)
org.freedesktop.import1.import
auth_admin:auth_admin:auth_admin_keep
org.freedesktop.import1.export
auth_admin:auth_admin:auth_admin_keep
@@ -836,6 +844,13 @@
org.freedesktop.policykit.pkexec.pantheon-files
auth_admin:auth_admin:auth_admin
org.freedesktop.policykit.pkexec.io.elementary.files
auth_admin:auth_admin:auth_admin
+# switchboard-plug-locale (bsc#1088472)
+org.pantheon.switchboard.locale.administration no:no:auth_admin_keep
+# switchboard-plug-security-privacy (bsc#1088472)
+polkit-untracked-privilege org.pantheon.security-privacy no:no:auth_admin_keep
+# switchboard-plug-useraccounts (bsc#1088472)
+org.pantheon.switchboard.user-accounts.administration no:no:auth_admin_keep
+
# scap-workbench (bsc#1084706)
scap-workbench-oscap.run auth_admin:auth_admin:auth_admin
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/polkit-default-privs-13.2/polkit-default-privs.standard
new/polkit-default-privs-13.2/polkit-default-privs.standard
--- old/polkit-default-privs-13.2/polkit-default-privs.standard 2018-06-22
15:27:54.000000000 +0200
+++ new/polkit-default-privs-13.2/polkit-default-privs.standard 2018-07-06
17:56:05.000000000 +0200
@@ -39,9 +39,6 @@
org.freedesktop.NetworkManager.settings.modify.global-dns
auth_admin_keep:auth_admin_keep:auth_admin_keep
#
-org.libvirt.unix.monitor yes
-org.libvirt.unix.manage
auth_admin_keep_always
-#
# gnome-settings-daemon (bnc#690496)
#
org.gnome.settingsdaemon.datetimemechanism.configure auth_admin_keep
@@ -419,7 +416,7 @@
org.cinnamon.settings-daemon.plugins.power.backlight-helper no:no:yes
org.cinnamon.settingsdaemon.datetimemechanism.configure
no:no:auth_admin_keep
-# blueman (bsc#1083066)
+# cinnamon settings-daemon (bsc#1083067)
org.cinnamon.settings-users auth_admin
# cinnamon-control-center (bsc#1090371)
@@ -531,7 +528,11 @@
# powerdevil (bnc#825256)
org.kde.powerdevil.backlighthelper.syspath no:yes:yes
-# libvirt (bnc#827644) ( original wants yes:yes:yes)
+#
+org.libvirt.unix.monitor yes
+org.libvirt.unix.manage
auth_admin_keep_always
+
+# libvirt (bnc#827644) (original wants yes:yes:yes)
org.libvirt.api.connect.getattr auth_admin_keep
org.libvirt.api.connect.read auth_admin_keep
org.libvirt.api.connect.search-domains auth_admin_keep
@@ -557,98 +558,6 @@
org.libvirt.api.storage-vol.getattr auth_admin_keep
org.libvirt.api.storage-vol.read auth_admin_keep
-# MATE settings-daemon (bnc#831404)
-org.mate.settingsdaemon.datetimemechanism.settimezone auth_admin_keep
-org.mate.settingsdaemon.datetimemechanism.settime auth_admin_keep
-org.mate.settingsdaemon.datetimemechanism.configurehwclock auth_admin_keep
-org.mate.randr.install-system-wide auth_admin_keep
-org.mate.power.backlight-helper
no:no:yes
-
-# gufw
-com.ubuntu.pkexec.gufw auth_admin
-
-# policycoreutils (bnc#848550)
-org.selinux.restorecon auth_admin_keep
-org.selinux.setenforce auth_admin_keep
-org.selinux.semanage auth_admin_keep
-org.selinux.change_default_policy auth_admin_keep
-org.selinux.change_policy_type auth_admin_keep
-org.selinux.config.pkexec.run no:no:auth_admin
-org.selinux.relabel_on_boot auth_admin_keep
-
-# policycoreutils (bnc#878631)
-org.selinux.customized no:no:yes
-org.selinux.semodule_list no:no:yes
-
-# kwallet (bnc#849739)
-
-org.kde.kcontrol.kcmkwallet.save no:no:yes
-
-# kwallet5 (bnc#1033296)
-
-org.kde.kcontrol.kcmkwallet5.save no:no:yes
-
-# baloo (bnc#866131)
-org.kde.baloo.filewatch.raiselimit no:no:auth_admin_keep
-
-# pcsc-lite (bnc#864178)
-org.debian.pcsc-lite.access_pcsc auth_admin:auth_admin:yes
-org.debian.pcsc-lite.access_card auth_admin:auth_admin:yes
-
-
-# firewalld (bnc#907625, bsc#971580)
-org.fedoraproject.FirewallD1.all auth_admin_keep
-org.fedoraproject.FirewallD1.info no:yes:yes
-org.fedoraproject.FirewallD1.config auth_admin_keep
-org.fedoraproject.FirewallD1.config.info auth_admin_keep
-org.fedoraproject.FirewallD1.direct auth_admin_keep
-org.fedoraproject.FirewallD1.direct.info auth_admin_keep
-org.fedoraproject.FirewallD1.policies auth_admin_keep
-org.fedoraproject.FirewallD1.policies.info auth_admin_keep
-
-
-# KDE5 powerdevil (bnc#912121)
-org.kde.powerdevil.backlighthelper.brightnessvalue no:yes:yes
-org.kde.powerdevil.backlighthelper.brightnessvaluemax no:yes:yes
-org.kde.powerdevil.backlighthelper.setbrightnessvalue no:no:yes
-
-# powerdevil action-name changes (bnc#927275)
-org.kde.powerdevil.backlighthelper.brightness no:yes:yes
-org.kde.powerdevil.backlighthelper.brightnessmax no:yes:yes
-org.kde.powerdevil.backlighthelper.setbrightness no:no:yes
-
-
-# storaged (bnc#915770)
-com.redhat.lvm2.create-logical-volume auth_admin_keep
-com.redhat.lvm2.delete-logical-volume auth_admin_keep
-com.redhat.lvm2.rename-logical-volume auth_admin_keep
-com.redhat.lvm2.resize-logical-volume auth_admin_keep
-com.redhat.lvm2.activate-logical-volume auth_admin_keep
-com.redhat.lvm2.deactivate-logical-volume auth_admin_keep
-com.redhat.lvm2.snapshot-logical-volume auth_admin_keep
-com.redhat.lvm2.create-volume-group auth_admin_keep
-com.redhat.lvm2.delete-volume-group auth_admin_keep
-com.redhat.lvm2.rename-volume-group auth_admin_keep
-com.redhat.lvm2.manage-lvm auth_admin_keep
-
-# systemd new things in 218
-org.freedesktop.systemd1.manage-units
auth_admin:auth_admin:auth_admin_keep
-org.freedesktop.systemd1.manage-unit-files
auth_admin:auth_admin:auth_admin_keep
-org.freedesktop.systemd1.reload-daemon
auth_admin:auth_admin:auth_admin_keep
-
-# gnome-multi-writer (bnc#924062)
-org.gnome.MultiWriter.probe
auth_admin:auth_admin:auth_admin_keep
-
-# realmd (bnc#916767)
-org.freedesktop.realmd.configure-realm
auth_admin:auth_admin:auth_admin_keep
-org.freedesktop.realmd.deconfigure-realm
auth_admin:auth_admin:auth_admin_keep
-org.freedesktop.realmd.login-policy
auth_admin:auth_admin:auth_admin_keep
-# realmd (bsc#1048025)
-org.freedesktop.realmd.discover-realm no:yes:yes
-
-# netvisix (bsc#930195)
-org.opensuse.policykit.netvisix
auth_admin:auth_admin:auth_admin
-
# libvirt (bsc#959297)
org.libvirt.api.connect.detect-storage-pools auth_admin_keep
org.libvirt.api.connect.getattr auth_admin_keep
@@ -790,6 +699,105 @@
org.libvirt.api.storage-vol.read auth_admin_keep
org.libvirt.api.storage-vol.resize auth_admin_keep
+# libvirt (bsc#1100328)
+org.libvirt.api.connect.search-nwfilter-bindings auth_admin_keep
+org.libvirt.api.nwfilter.binding-getattr auth_admin_keep
+org.libvirt.api.nwfilter.binding-read auth_admin_keep
+org.libvirt.api.nwfilter.binding-create no
+org.libvirt.api.nwfilter.binding-delete no
+
+# MATE settings-daemon (bnc#831404)
+org.mate.settingsdaemon.datetimemechanism.settimezone auth_admin_keep
+org.mate.settingsdaemon.datetimemechanism.settime auth_admin_keep
+org.mate.settingsdaemon.datetimemechanism.configurehwclock auth_admin_keep
+org.mate.randr.install-system-wide auth_admin_keep
+org.mate.power.backlight-helper
no:no:yes
+
+# gufw
+com.ubuntu.pkexec.gufw auth_admin
+
+# policycoreutils (bnc#848550)
+org.selinux.restorecon auth_admin_keep
+org.selinux.setenforce auth_admin_keep
+org.selinux.semanage auth_admin_keep
+org.selinux.change_default_policy auth_admin_keep
+org.selinux.change_policy_type auth_admin_keep
+org.selinux.config.pkexec.run no:no:auth_admin
+org.selinux.relabel_on_boot auth_admin_keep
+
+# policycoreutils (bnc#878631)
+org.selinux.customized no:no:yes
+org.selinux.semodule_list no:no:yes
+
+# kwallet (bnc#849739)
+
+org.kde.kcontrol.kcmkwallet.save no:no:yes
+
+# kwallet5 (bnc#1033296)
+
+org.kde.kcontrol.kcmkwallet5.save no:no:yes
+
+# baloo (bnc#866131)
+org.kde.baloo.filewatch.raiselimit no:no:auth_admin_keep
+
+# pcsc-lite (bnc#864178)
+org.debian.pcsc-lite.access_pcsc auth_admin:auth_admin:yes
+org.debian.pcsc-lite.access_card auth_admin:auth_admin:yes
+
+
+# firewalld (bnc#907625, bsc#971580)
+org.fedoraproject.FirewallD1.all auth_admin_keep
+org.fedoraproject.FirewallD1.info no:yes:yes
+org.fedoraproject.FirewallD1.config auth_admin_keep
+org.fedoraproject.FirewallD1.config.info auth_admin_keep
+org.fedoraproject.FirewallD1.direct auth_admin_keep
+org.fedoraproject.FirewallD1.direct.info auth_admin_keep
+org.fedoraproject.FirewallD1.policies auth_admin_keep
+org.fedoraproject.FirewallD1.policies.info auth_admin_keep
+
+
+# KDE5 powerdevil (bnc#912121)
+org.kde.powerdevil.backlighthelper.brightnessvalue no:yes:yes
+org.kde.powerdevil.backlighthelper.brightnessvaluemax no:yes:yes
+org.kde.powerdevil.backlighthelper.setbrightnessvalue no:no:yes
+
+# powerdevil action-name changes (bnc#927275)
+org.kde.powerdevil.backlighthelper.brightness no:yes:yes
+org.kde.powerdevil.backlighthelper.brightnessmax no:yes:yes
+org.kde.powerdevil.backlighthelper.setbrightness no:no:yes
+
+
+# storaged (bnc#915770)
+com.redhat.lvm2.create-logical-volume auth_admin_keep
+com.redhat.lvm2.delete-logical-volume auth_admin_keep
+com.redhat.lvm2.rename-logical-volume auth_admin_keep
+com.redhat.lvm2.resize-logical-volume auth_admin_keep
+com.redhat.lvm2.activate-logical-volume auth_admin_keep
+com.redhat.lvm2.deactivate-logical-volume auth_admin_keep
+com.redhat.lvm2.snapshot-logical-volume auth_admin_keep
+com.redhat.lvm2.create-volume-group auth_admin_keep
+com.redhat.lvm2.delete-volume-group auth_admin_keep
+com.redhat.lvm2.rename-volume-group auth_admin_keep
+com.redhat.lvm2.manage-lvm auth_admin_keep
+
+# systemd new things in 218
+org.freedesktop.systemd1.manage-units
auth_admin:auth_admin:auth_admin_keep
+org.freedesktop.systemd1.manage-unit-files
auth_admin:auth_admin:auth_admin_keep
+org.freedesktop.systemd1.reload-daemon
auth_admin:auth_admin:auth_admin_keep
+
+# gnome-multi-writer (bnc#924062)
+org.gnome.MultiWriter.probe
auth_admin:auth_admin:auth_admin_keep
+
+# realmd (bnc#916767)
+org.freedesktop.realmd.configure-realm
auth_admin:auth_admin:auth_admin_keep
+org.freedesktop.realmd.deconfigure-realm
auth_admin:auth_admin:auth_admin_keep
+org.freedesktop.realmd.login-policy
auth_admin:auth_admin:auth_admin_keep
+# realmd (bsc#1048025)
+org.freedesktop.realmd.discover-realm no:yes:yes
+
+# netvisix (bsc#930195)
+org.opensuse.policykit.netvisix
auth_admin:auth_admin:auth_admin
+
# importd (bsc#964935)
org.freedesktop.import1.import
auth_admin:auth_admin:auth_admin_keep
org.freedesktop.import1.export
auth_admin:auth_admin:auth_admin_keep
@@ -904,6 +912,13 @@
org.freedesktop.policykit.pkexec.pantheon-files
auth_admin:auth_admin:auth_admin
org.freedesktop.policykit.pkexec.io.elementary.files
auth_admin:auth_admin:auth_admin
+# switchboard-plug-locale (bsc#1088472)
+org.pantheon.switchboard.locale.administration no:no:auth_admin_keep
+# switchboard-plug-security-privacy (bsc#1088472)
+polkit-untracked-privilege org.pantheon.security-privacy no:no:auth_admin_keep
+# switchboard-plug-useraccounts (bsc#1088472)
+org.pantheon.switchboard.user-accounts.administration no:no:auth_admin_keep
+
# scap-workbench (bsc#1084706)
scap-workbench-oscap.run
auth_admin_keep:auth_admin_keep:auth_admin_keep