Bug 1882380

Summary: Please allow `NM.Device.get_applied_connection_async()` to run by non-privilege user
Product: Red Hat Enterprise Linux 8 Reporter: Gris Ge <fge>
Component: NetworkManagerAssignee: Thomas Haller <thaller>
Status: CLOSED ERRATA QA Contact: Desktop QE <desktop-qa-list>
Severity: medium Docs Contact:
Priority: medium    
Version: 8.4CC: acardace, atragler, bgalvani, lrintel, rkhan, sukulkar, thaller, till, vbenes
Target Milestone: rcKeywords: Triaged
Target Release: 8.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: NetworkManager-1.30.0-0.1.el8 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-05-18 13:29:41 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Gris Ge 2020-09-24 12:32:37 UTC
Description of problem:


Version-Release number of selected component (if applicable):


How reproducible:


Steps to Reproduce:
1.
2.
3.

Actual results:


Expected results:


Additional info:

Comment 1 Gris Ge 2020-09-24 12:33:56 UTC
Just nice to have. Not a must.

Comment 2 Thomas Haller 2020-09-24 12:40:12 UTC
A completely non-previledged user shouldn't be able to change the system. Some previledges are required, and we use polkit permissions for that.

Currently you need "org.freedesktop.NetworkManager.network-control" permissions.

What is your use-case, and why does your user not have the required permission?

Comment 3 Thomas Haller 2020-09-24 12:41:13 UTC
a "get_applied_connection_async". Sorry. Yes, that makes sense...

Comment 4 Thomas Haller 2020-09-24 12:44:23 UTC
(In reply to Thomas Haller from comment #3)
> a "get_applied_connection_async". Sorry. Yes, that makes sense...

also because a non-prejudicial user can look at the connection profiles...

Comment 5 Gris Ge 2020-09-24 15:32:55 UTC
The non-privileged user should able to see the applied connection profiles.

Comment 7 Thomas Haller 2020-09-29 09:52:43 UTC
merged to upstream master, before 1.28.0

https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/634

Comment 14 errata-xmlrpc 2021-05-18 13:29:41 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Moderate: NetworkManager and libnma security, bug fix, and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2021:1574