fix(security): VPLUS-2026-34718 - fix DBus permission configuration#658
fix(security): VPLUS-2026-34718 - fix DBus permission configuration#658deepin-bot[bot] merged 1 commit intolinuxdeepin:masterfrom
Conversation
Implement method-level permission separation for DBus service Default deny policy for all methods Whitelist read-only methods (getAuthorizedInfo, getRemoveInfo, etc.) Dangerous methods (aptUpdate, installDriver, disableInDevice) require authentication Add comprehensive security policy documentation Security impact: Fixes privilege escalation vulnerability (CVSS 8.1) Prevents unauthorized access to root-level operations Clear maintenance guidelines for future DBus method additions CVSS: 8.1 (High) Affected: All systems with deepin-devicemanager installed PMS: TASK-389221
deepin pr auto review这份 1. 代码逻辑与安全性审查整体评价: 具体分析:
2. 代码质量审查
3. 代码性能审查
4. 潜在风险与改进建议尽管这次修改在安全性上有了很大提升,但仍有几点需要特别注意:
总结这份 最终建议: |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: add-uos, lzwind The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
/merge |
Implement method-level permission separation for DBus service Default deny policy for all methods
Whitelist read-only methods (getAuthorizedInfo, getRemoveInfo, etc.)
Dangerous methods (aptUpdate, installDriver, disableInDevice) require authentication Add comprehensive security policy documentation
Security impact:
Fixes privilege escalation vulnerability (CVSS 8.1) Prevents unauthorized access to root-level operations Clear maintenance guidelines for future DBus method additions
CVSS: 8.1 (High)
Affected: All systems with deepin-devicemanager installed
PMS: TASK-389221