Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

skypeforlinux: Whitelist downloads directory #4807

Merged
merged 1 commit into from
Jan 4, 2022

Conversation

WhyNotHugo
Copy link
Contributor

The downloads directory is used by skype to download files send by other parties.

It's used when saving files send in conversations.
@@ -6,7 +6,6 @@ include skypeforlinux.local
include globals.local

# Disabled until someone reported positive feedback
ignore whitelist ${DOWNLOADS}
ignore include whitelist-common.inc
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should remove this too.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

whitelist-common.inc grants write access to .config/dconf, and this sounds like it could be abused to run arbitrary commands (for example, by changing the default terminal).

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  1. read-only ${HOME}/.config/dconf
  2. Who cares about such hacks for a profile which allows systemd-run & co.

@netblue30 netblue30 merged commit 732282e into netblue30:master Jan 4, 2022
@netblue30
Copy link
Owner

Thanks for the fix!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants