Your message dated Tue, 31 Mar 2015 18:48:45 +0000 with message-id <[email protected]> and subject line Bug#780004: fixed in udisks2 2.1.5-2 has caused the Debian Bug report #780004, regarding udisks2: rules for devices on this seat / other seat interact poorly with dbus-user-session to be marked as done.
This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected] immediately.) -- 780004: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=780004 Debian Bug Tracking System Contact [email protected] with problems
--- Begin Message ---Package: udisks2 Version: 2.1.3-5 Severity: normal Tags: upstream udisks2's logic for whether I may do something to a device looks like this pseudocode: let requesting_seat = requesting process -> session -> seat let device_seat = device -> seat if (device_seat && requesting_seat && requesting_seat == device_seat) { use a polkit rule like org.freedesktop.udisks2.filesystem-mount (by default, requires either an active session or admin authentication) } else { use a polkit rule like org.freedesktop.udisks2.filesystem-mount-other-seat (by default, requires admin authentication regardless) } This works poorly with the "user session" model used by dbus-user-session, which the systemd/kdbus developers intend to be the only model supported with kdbus. In that model, shared per-user services like gvfs and gnome-terminal exist outside any particular login session, and are not associated with a seat; the practical result is that while using dbus-user-session, I always need to enter my password to mount a disk, because gvfs' udisks backend is a child process of my `systemd --user` rather than part of my GUI session. One possibility for fixing this would be to change the pseudocode to this: let device_seat = device->seat if (device_seat) { for session in requesting uid's active sessions { if session->seat && session->seat == device_seat { use a polkit rule like org.freedesktop.udisks2.filesystem-mount return } } } use a polkit rule like org.freedesktop.udisks2.filesystem-mount-other-seat with the justification that different sessions with the same uid do not really represent a security boundary. There is a bit of a subtlety here with active vs. inactive sessions: if you have "fast user switching" on seat0, and this situation: seat0 \- active (tty7): alice \- inactive (tty8): bob seat1 or ssh session \- active: bob then bob should not be able to manipulate seat0 devices (without admin authentication) until alice finishes using seat0 and returns to bob's (locked) session. Thoughts? S
--- End Message ---
--- Begin Message ---Source: udisks2 Source-Version: 2.1.5-2 We believe that the bug you reported is fixed in the latest version of udisks2, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to [email protected], and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Simon McVittie <[email protected]> (supplier of updated udisks2 package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing [email protected]) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 31 Mar 2015 19:16:58 +0100 Source: udisks2 Binary: udisks2 udisks2-doc libudisks2-0 libudisks2-dev gir1.2-udisks-2.0 Architecture: all source Version: 2.1.5-2 Distribution: experimental Urgency: medium Maintainer: Utopia Maintenance Team <[email protected]> Changed-By: Simon McVittie <[email protected]> Closes: 780004 Description: gir1.2-udisks-2.0 - GObject based library to access udisks2 - introspection data libudisks2-0 - GObject based library to access udisks2 libudisks2-dev - GObject based library to access udisks2 - development files udisks2 - D-Bus service to access and manipulate storage devices udisks2-doc - udisks2 documentation Changes: udisks2 (2.1.5-2) experimental; urgency=medium . * Team upload. * Treat devices as "on the same seat" if the requesting uid owns the active login session on the device's seat. This means that shared services run by the user's `systemd --user`, such as the dbus-daemon run by dbus-user-session and the D-Bus or systemd services that it starts, can manipulate the user's devices even though those are not associated with any particular login session or seat. (Closes: #780004) Checksums-Sha1: 0be1cddf9ae3e4e2c9c27c222d50d7ffba349f69 2563 udisks2_2.1.5-2.dsc f35be6dd3010df45a0da57115f27be51a2482027 15532 udisks2_2.1.5-2.debian.tar.xz de398a72b820cd450a4ae7f4918ed0160f336440 188094 udisks2-doc_2.1.5-2_all.deb Checksums-Sha256: d9cf94927764585da95f48d327a9e1cb6d8a34080d3b31f79e795043350dc5eb 2563 udisks2_2.1.5-2.dsc d620e9781dbb7888686338c1ff15f107063cd2b3efa6f351bba9e1086a65c25a 15532 udisks2_2.1.5-2.debian.tar.xz b6c6d450e3c51e12b8c8fd427ab21f6eef136315686de0efe804414f10a88297 188094 udisks2-doc_2.1.5-2_all.deb Files: 1307426ea1e66f2b9cc2f1d56a4e4e8a 2563 admin optional udisks2_2.1.5-2.dsc b885962968208caf560bb2b46a78463d 15532 admin optional udisks2_2.1.5-2.debian.tar.xz 6f9b8f62ceff0c726b7df11556f61965 188094 doc optional udisks2-doc_2.1.5-2_all.deb -----BEGIN PGP SIGNATURE----- iQIVAwUBVRrps03o/ypjx8yQAQiNUA//bN20xeRqwqaohEZqV/kMWdFh05czP8Jh gJzMt5hQNLVbgz7b/ErAT0rH71+C8gzAnRBdOw11OGrZC1zWgHXDP4zetELXQrtR 8sKm0lIW29POgo4rT12+ByekSc14z4M2HrDocNBTW86MUa80rDzpREKTgqbY1sCY BaG3DMMNXiBjZt4DmgVmNKGHdS1HrDju7SidQ7KxioFwwkaJMBUl6eOp5SKxQzCZ sioOVLiO1idycGcgiGgIDeaJnmHtcv8S3ayfSp3cZVnyBmAyunJ617PkzYnyx5kh ygYpzhGwHoz7bCDIGvY3IoMr3VdU0UOiSmRhopnGs6gt0m6u0HjL/LZjMiITCHV/ yWDafMtfNp1KpaiK99CSneNoKZqT+FmXuJ/o/7YUOAoVlbQK49jlKvqy/ALswGjp tKWcrs+HgQ1TRJRwa0H17tw05U4PMglTTAArxFPrw9I9QEt/szGacuJqPdUHkvRq Ozvu95idxal/DK+owqgx2WPqNNyI+Sg+Ac6kHMd0cA4tGN96Y37OiowqW1yENBLT uZ9EZWsMB15omEmBdvwE/SUliWJJAs2kSllySV6ypjyLTtyJ4jSrliJhrEzEnrk+ 5qPx5StLs3A3z2fO1BkF3odJq6mvq+LwBXjYlGnsYS/O3HwfL+xKL7aFka0FuS8j ujtT9uTiX9o= =LqsX -----END PGP SIGNATURE-----
--- End Message ---
_______________________________________________ Pkg-utopia-maintainers mailing list [email protected] http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-utopia-maintainers
