Dear Maintainer,
this issue crops up time and time again and is not exclusive to dist
upgrades. The following rule randomly appears when running `usbguard
list-rules`:
9: allow id *:* label 'GNOME_SETTINGS_DAEMON_RULE"
I removed the rule multiple times on the same system, yet
somehow it reappears, tho quite infrequently. I have not yet been able
to point out what causes the rule to be added, only that it happens
automatically, without user trigger.
I want to stress the severity of the issue. I am using this laptop for
presentations, where I often plug external drives into it from third
parties. I use usbguard to block all input devices possibly
masquarading as mass storage devices. The rule in question allows ALL
devices automatically, severly undermining my security.
I also question upstreams intention with such a rule. Dconf has limited
control over usbguard. The inital report mentions setting
`org.gnome.desktop.privacy usb-protection-level` to `always`. This is a
workaround, not a solution! In no state should Gnome's usb protection
settings override other usbguard rules from other sources.
This workaround also has no effect when usb protection on Gnome is
disabled. I have the following gsettings from install, on all users, no
changes made to them since:
org.gnome.desktop.privacy usb-protection false
org.gnome.desktop.privacy usb-protection-level lockscreen
yet the offending rule often reappears.
from: jan kapoli