Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Tracking bug: RBAC for KDE Plasma #192

Open
6 of 17 tasks
secureworkstation opened this issue Jan 29, 2020 · 1 comment
Open
6 of 17 tasks

Tracking bug: RBAC for KDE Plasma #192

secureworkstation opened this issue Jan 29, 2020 · 1 comment

Comments

@secureworkstation
Copy link
Contributor

secureworkstation commented Jan 29, 2020

I'm working on making RBAC work in KDE Plasma. This is a tracking bug for all the effort I make towards the goal.

Small PRs for selinux-policy-contrib:

Small PRs for selinux-policy:

Transitioning for kwalletd5 (when launched by PAM):

KDE Plasma policy:

  • Confinement for kdeconnect
  • Confinement for kwalletd5
  • Main patchset prepared
  • Main patchset merged

Overall:

  • KDE Plasma testable in RBAC enforcing
  • Make a test suite
  • KDE Plasma correctly working in RBAC enforcing

Related proposals:

  • Labeling for wayland
  • Labeling for session systemd
@secureworkstation
Copy link
Contributor Author

secureworkstation commented Feb 3, 2020

Good news: it starts with 0 sealerts in RBAC enforcing :)
And same with gnome-shell running kdeconnect and kwallet on X11 on sddm.
And (almost) same with gnome-shell running both on X11 and Wayland on gdm.
And (almost) same with KDE Plasma on X11 on gdm.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants