GKSU apps launch root apps from About dialog

Bug #1006002 reported by Danielle Foré
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
Granite
Invalid
Wishlist
Unassigned

Bug Description

When an app runs as GKSU, the About dialog launches a root owned web browser. If possible, we shouldn't do this.

Revision history for this message
xapantu (xapantu) wrote : Re: [Bug 1006002] [NEW] GKSU apps launch root apps from About dialog

 importance whishlist

You can't really avoid that, it could work with sudo (and I am not even
sure), but I doubt it could with su. Anyway, no apps should be launched
as root. Everything in policykit quickly, please !

Yet, it could be investigated, even if I think there aren't a lot of
chances.

Le mardi 29 mai 2012 à 16:41 +0000, Daniel Fore a écrit :
> Public bug reported:
>
> When an app runs as GKSU, the About dialog launches a root owned web
> browser. If possible, we shouldn't do this.
>
> ** Affects: granite
> Importance: Undecided
> Status: New
>

Revision history for this message
Sergey "Shnatsel" Davidoff (shnatsel) wrote :

Dropping privileges is nasty indeed.

Cody Garver (codygarver)
Changed in granite:
importance: Undecided → Wishlist
status: New → Confirmed
tags: added: privileges root
tags: added: about
Revision history for this message
Akshay Shekher (voldyman) wrote :

to which group and user should the permissions be dropped to?

Changed in granite:
assignee: nobody → Sergey "Shnatsel" Davidoff (shnatsel)
Revision history for this message
Sergey "Shnatsel" Davidoff (shnatsel) wrote :

To the user with UID from SUDO_UID environment variable in case of gksudo and PKEXEC_UID environment variable in case of pkexec (which is a more modern way of doing basically the same thing; it uses policykit as a backend).

Changed in granite:
assignee: Sergey "Shnatsel" Davidoff (shnatsel) → nobody
Revision history for this message
Sergey "Shnatsel" Davidoff (shnatsel) wrote :

Using su is not allowed to mere users on Ubuntu, and "sudo su" provides SUDO_UID variable.

Also, I don't know why I used to be against dropping privileges. This actually sounds sane now. I have a much hackier (though working) code in Glimpse for that; gotta fix it with these new findings.

Revision history for this message
Danielle Foré (danrabbit) wrote :

Marking this as invalid for Granite. Now that we launch root apps using Polkit and/or the About dialog is launched from quicklist I can't seem to reproduce this issue.

Changed in granite:
status: Confirmed → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.