Comment 52 for bug 306362

Revision history for this message
Scott James Remnant (Canonical) (canonical-scott) wrote :

This change is known to break many of the existing D-Bus services, most notably Avahi, PolicyKit and PackageKit. It's also believed to break signals.

While upstream figure out what to do about that, we've looked into the actual effect of the problem.

The most concerning system bus service would be system-tools-backend, however that has explicit <deny> rules, so should not be affected.

Other pieces already use PolicyKit.

Thus we're happy that there's no significant exploit here, and that there is too great a risk for breaking existing services with the current patch. We'll make an upload as soon as the situation is clear.