libera/#devuan-dev/ Wednesday, 2019-07-17

amesserhi there, been off for quite a while now, is there a list about things todo for beowulf?21:48
fsmithredmeeting is in 45 minutes (20:30 UTC)21:48
amesseryes i know. I'm sorry, but this is too late for me at the moment21:51
amesseralso, since i'm not very good in english speaking - and listening - it was always hard for me to follow the native speakers21:51
fsmithredoh, sorry21:51
amesserespecially since the signal to noise ratio was sometimes not very high21:52
fsmithredlol, true21:52
fsmithredcan I pick your brain about policykit right now?21:52
amesseryeah, give it a try21:53
fsmithreddevuan desktop theme includes a fix to un-do the gtk3 disappearing scrollbars21:53
fsmithredfix works for user21:53
fsmithredin root apps, like synaptic, pkexec does not pass env variables, so the scrollbars come and go21:54
fsmithredone workaround involves changing which variable pkexec will pass, and there's discussion about what is safe or not safe.21:54
fsmithredAll beyond my understanding21:54
fsmithredif you feel up to looking into it, I could give you some links to the discussions21:55
amesserok, i can have a look at it21:55
fsmithredthanks21:55
fsmithredMy post to xfce forum: https://forum.xfce.org/viewtopic.php?pid=53417#p5341721:57
fsmithredanswer linked me to this: https://bugzilla.redhat.com/show_bug.cgi?id=117177921:57
fsmithredand this: https://bugs.freedesktop.org/show_bug.cgi?id=96713#c321:57
fsmithredthe scrollbar fix is a few posts above mine21:58
amesserI like the comment:22:14
amesser    /* By default we don't allow running X11 apps, as it does not work in the general case. See ...22:15
amesserjust above the X11 vars passed :-)22:15
amesserpkexec is not to be supposed to be run with X11 apps - but that is the typicall usecase22:15
amesserit is sued today :-)22:15
amessers/sued/used22:16
fsmithredyeah, there's not a lot of point to using synaptic or gparted if you can't have root privs22:17
amesserthe point about passing these vars from user to root context using pkexec is, that basically a user could be set the var to some bogus value in order to trigger a leak/security issue in the program and use this to lauch e.g. a root shell22:19
fsmithredthanks, that makes sense22:20
fsmithredmy solution is to open a root shell22:20
fsmithredwith 'su' the scrollbar fix works.22:20
amesserbut, someone who is allowed to run synaptic as root can mess the system anyway22:21
fsmithredyeah22:21
fsmithredgparted, too22:21
amesserfor some of the vars, they have added value checking22:21
amesseri think it would be safe if we add these vars and add checking their values22:22
fsmithredcool22:22
amesserhttps://gitlab.freedesktop.org/polkit/polkit/blob/master/src/programs/pkexec.c, function validate_environment_variable22:23
fsmithredare you packaging policykit these days?22:23
golinuxfsmithred: Thanks for following up on this22:24
golinuxand to amesser for joinging in22:25
amesserI havn't doing any packaging for a couple of months now, but at least i'm set as developer for https://git.devuan.org/devuan-packages/policykit-1/22:25
amesserso i could try making a branch of it and implement some thing for test at least22:26
fsmithredgreat, thanks22:26
amesseryou're welcome, golinux22:28
amesserI'll try to do it until the weekend...22:28
plasma41About time for a meeting22:29
golinuxGood to see you after so long.22:29
fsmithredsomebody else go first22:29
golinuxThe time is now folks!!22:35

Generated by irclog2html.py 2.17.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!