/srv/irclogs.ubuntu.com/2022/05/27/#kubuntu-devel.txt

BluesKajHi all12:17
EickmeyerRikMills: How do you want to tackle the kdesu SRU? I might be able to handle the bug description, and can definitely handle the upload for ubuntustudio-default-settings, it's up to you if you want me to do anything with kubuntu-settings and/or kdesu.18:10
RikMillsEickmeyer: I would like to handle the bug description and kdesu upload. I am pondering at the moment quite how to word it, hence me not leaping immediately to do it. I will think over the weekend and get it done on Monday18:54
EickmeyerRikMills: Ok, that's fair.18:55
RikMillsEickmeyer: also, fyi: https://salsa.debian.org/qt-kde-team/kde/kdesu/-/merge_requests/319:01
ubottuMerge 3 in qt-kde-team/kde/kdesu "Disable use of sudo 'Defaults use_pty' for kdesu" [Opened]19:01
EickmeyerRikMills: Oh, cool. Hopefully they'll actually merge it.19:02
RikMillsif that gets accepted, it will make a Ubuntu SRU more 'palatable'19:02
RikMillsas the debian dev who made the sudo config change seems onboard19:03
EickmeyerYeah, that's great. Also, we got approval from the security team, although it would be nice to get that in the bug report.19:03
EickmeyerIt would give the SRU more teeth.19:04
RikMillsYeah, I want to avoid the whole "kdesu works by exploiting a CVE exploit" narrative19:04
RikMillsnot only is that a red flag, I am not 100% convinced it is true19:05
EickmeyerI mean, it is true, but it's also accidental.19:05
EickmeyerI don't for an instant think anybody meant to make it that way.19:06
RikMillsI think it quite possible that the breakage is a coincidental consequence, and not specificall that kdesu relies on the exploit to work19:07
RikMillsi.e. the fix has other consequences19:07
EickmeyerYeah, that could be true too.19:08
RikMillsanyway, I want to try to avoid that that being expressed in the SRU19:08
RikMillshence me thinking hard how to word it19:08
arraybolt3RikMills: Just throwing this out there, you could say that kdesu is relying on behavior that is sometimes considered unexpected in order to function properly, and that the change in sudo is causing that unexpected behavior to fail, thus resulting in a loss of functionality. (I dunno how SRUs work, this is just a random idea.) Whether kdesu *is* exploiting a CVE on accident, or the CVE fix simply messes something else up, either way the behavior19:11
arraybolt3 is considered unexpected when the CVE fix is in place, thus why it needs removed.19:11
EickmeyerRikMills: Sure, no objection to that.19:13
arraybolt3(Really, though, I wish someone would just figure out how lxqt-sudo is handling the situation and then change kdesu to match. If I knew C++, I19:13
RikMillsconsiderign I have not yet found another distro with KDE that sets that sudoers config option, I am fairly sure we are on not too shaky ground 19:13
arraybolt3I'd take a swing at it, but...)19:13
RikMillsarraybolt3: I wish my C++ was up to it also ;)19:14

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!