NetworkManager/po/POTFILES.in
Íñigo Huguet 0b75d905e5 polkit: remove the modify_system build option
This build option allowed non-admin users to create system-wide
connections. Generally, this is not a good idea as system-wide changes
should be done by administrators.

However, the main reason for the change is that this can be used to
bypass filesystem permissions, among possibly other attacks. As the
daemon runs as root, a user can create a system-wide connection that
uses a certificate from a different user to authenticate in a WiFi
network protected with 802.1X or a VPN, because as root user the daemon
can access to the file.

This patch does not completely fix the issue, as users can still create
private connections specifying a path to another user's connection. This
will be addressed in other patch. However, this patch is needed too,
because in system-wide connections we don't store which user created the
connection, so there woudn't be any way to check his/her permissions.

This is part of the fix for CVE-2025-9615

See: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/issues/1809
2025-12-12 12:38:48 +01:00

205 lines
7.3 KiB
Text

# List of source files containing translatable strings.
# Please keep this file sorted alphabetically.
data/org.freedesktop.NetworkManager.policy.in
src/core/NetworkManagerUtils.c
src/core/devices/adsl/nm-device-adsl.c
src/core/devices/bluetooth/nm-bluez-manager.c
src/core/devices/bluetooth/nm-device-bt.c
src/core/devices/nm-device-6lowpan.c
src/core/devices/nm-device-bond.c
src/core/devices/nm-device-bridge.c
src/core/devices/nm-device-dummy.c
src/core/devices/nm-device-ethernet-utils.c
src/core/devices/nm-device-ethernet.c
src/core/devices/nm-device-infiniband.c
src/core/devices/nm-device-ip-tunnel.c
src/core/devices/nm-device-loopback.c
src/core/devices/nm-device-macvlan.c
src/core/devices/nm-device-tun.c
src/core/devices/nm-device-veth.c
src/core/devices/nm-device-vlan.c
src/core/devices/nm-device-vrf.c
src/core/devices/nm-device-vxlan.c
src/core/devices/nm-device-wpan.c
src/core/devices/team/nm-device-team.c
src/core/devices/wifi/nm-device-olpc-mesh.c
src/core/devices/wifi/nm-device-wifi.c
src/core/devices/wifi/nm-wifi-utils.c
src/core/devices/wwan/nm-modem-broadband.c
src/core/dhcp/nm-dhcp-dhclient-utils.c
src/core/dhcp/nm-dhcp-dhclient.c
src/core/dhcp/nm-dhcp-manager.c
src/core/dns/nm-dns-manager.c
src/core/main-utils.c
src/core/main.c
src/core/nm-config.c
src/core/nm-manager.c
src/core/settings/plugins/ifcfg-rh/nms-ifcfg-rh-reader.c
src/core/settings/plugins/ifcfg-rh/tests/test-ifcfg-rh.c
src/libnm-client-impl/nm-client.c
src/libnm-client-impl/nm-conn-utils.c
src/libnm-client-impl/nm-device-6lowpan.c
src/libnm-client-impl/nm-device-adsl.c
src/libnm-client-impl/nm-device-bond.c
src/libnm-client-impl/nm-device-bridge.c
src/libnm-client-impl/nm-device-bt.c
src/libnm-client-impl/nm-device-dummy.c
src/libnm-client-impl/nm-device-ethernet.c
src/libnm-client-impl/nm-device-generic.c
src/libnm-client-impl/nm-device-hsr.c
src/libnm-client-impl/nm-device-infiniband.c
src/libnm-client-impl/nm-device-ip-tunnel.c
src/libnm-client-impl/nm-device-loopback.c
src/libnm-client-impl/nm-device-macvlan.c
src/libnm-client-impl/nm-device-modem.c
src/libnm-client-impl/nm-device-olpc-mesh.c
src/libnm-client-impl/nm-device-ovs-bridge.c
src/libnm-client-impl/nm-device-ovs-interface.c
src/libnm-client-impl/nm-device-ovs-port.c
src/libnm-client-impl/nm-device-team.c
src/libnm-client-impl/nm-device-tun.c
src/libnm-client-impl/nm-device-veth.c
src/libnm-client-impl/nm-device-vlan.c
src/libnm-client-impl/nm-device-vrf.c
src/libnm-client-impl/nm-device-vxlan.c
src/libnm-client-impl/nm-device-wifi-p2p.c
src/libnm-client-impl/nm-device-wifi.c
src/libnm-client-impl/nm-device-wimax.c
src/libnm-client-impl/nm-device-wpan.c
src/libnm-client-impl/nm-device.c
src/libnm-client-impl/nm-object.c
src/libnm-client-impl/nm-remote-connection.c
src/libnm-client-impl/nm-secret-agent-old.c
src/libnm-client-impl/nm-vpn-plugin-old.c
src/libnm-client-impl/nm-vpn-service-plugin.c
src/libnm-core-aux-extern/nm-libnm-core-aux.c
src/libnm-core-aux-intern/nm-libnm-core-utils.c
src/libnm-core-impl/nm-connection.c
src/libnm-core-impl/nm-keyfile-utils.c
src/libnm-core-impl/nm-keyfile.c
src/libnm-core-impl/nm-setting-6lowpan.c
src/libnm-core-impl/nm-setting-8021x.c
src/libnm-core-impl/nm-setting-adsl.c
src/libnm-core-impl/nm-setting-bluetooth.c
src/libnm-core-impl/nm-setting-bond-port.c
src/libnm-core-impl/nm-setting-bond.c
src/libnm-core-impl/nm-setting-bridge-port.c
src/libnm-core-impl/nm-setting-bridge.c
src/libnm-core-impl/nm-setting-cdma.c
src/libnm-core-impl/nm-setting-connection.c
src/libnm-core-impl/nm-setting-dcb.c
src/libnm-core-impl/nm-setting-ethtool.c
src/libnm-core-impl/nm-setting-generic.c
src/libnm-core-impl/nm-setting-gsm.c
src/libnm-core-impl/nm-setting-hsr.c
src/libnm-core-impl/nm-setting-infiniband.c
src/libnm-core-impl/nm-setting-ip-config.c
src/libnm-core-impl/nm-setting-ip-tunnel.c
src/libnm-core-impl/nm-setting-ipvlan.c
src/libnm-core-impl/nm-setting-ip4-config.c
src/libnm-core-impl/nm-setting-ip6-config.c
src/libnm-core-impl/nm-setting-loopback.c
src/libnm-core-impl/nm-setting-macsec.c
src/libnm-core-impl/nm-setting-macvlan.c
src/libnm-core-impl/nm-setting-match.c
src/libnm-core-impl/nm-setting-olpc-mesh.c
src/libnm-core-impl/nm-setting-ovs-bridge.c
src/libnm-core-impl/nm-setting-ovs-dpdk.c
src/libnm-core-impl/nm-setting-ovs-external-ids.c
src/libnm-core-impl/nm-setting-ovs-interface.c
src/libnm-core-impl/nm-setting-ovs-other-config.c
src/libnm-core-impl/nm-setting-ovs-patch.c
src/libnm-core-impl/nm-setting-ovs-port.c
src/libnm-core-impl/nm-setting-ppp.c
src/libnm-core-impl/nm-setting-pppoe.c
src/libnm-core-impl/nm-setting-proxy.c
src/libnm-core-impl/nm-setting-sriov.c
src/libnm-core-impl/nm-setting-tc-config.c
src/libnm-core-impl/nm-setting-team-port.c
src/libnm-core-impl/nm-setting-team.c
src/libnm-core-impl/nm-setting-tun.c
src/libnm-core-impl/nm-setting-user.c
src/libnm-core-impl/nm-setting-veth.c
src/libnm-core-impl/nm-setting-vlan.c
src/libnm-core-impl/nm-setting-vpn.c
src/libnm-core-impl/nm-setting-vrf.c
src/libnm-core-impl/nm-setting-vxlan.c
src/libnm-core-impl/nm-setting-wifi-p2p.c
src/libnm-core-impl/nm-setting-wimax.c
src/libnm-core-impl/nm-setting-wired.c
src/libnm-core-impl/nm-setting-wireguard.c
src/libnm-core-impl/nm-setting-wireless-security.c
src/libnm-core-impl/nm-setting-wireless.c
src/libnm-core-impl/nm-setting-wpan.c
src/libnm-core-impl/nm-setting.c
src/libnm-core-impl/nm-team-utils.c
src/libnm-core-impl/nm-utils.c
src/libnm-core-impl/nm-vpn-editor-plugin.c
src/libnm-core-impl/nm-vpn-plugin-info.c
src/libnm-crypto/nm-crypto-gnutls.c
src/libnm-crypto/nm-crypto-nss.c
src/libnm-crypto/nm-crypto-null.c
src/libnm-crypto/nm-crypto.c
src/libnm-glib-aux/nm-dbus-aux.c
src/libnm-glib-aux/nm-shared-utils.c
src/libnm-log-core/nm-logging.c
src/libnmc-base/nm-client-utils.c
src/libnmc-base/nm-polkit-listener.c
src/libnmc-base/nm-secret-agent-simple.c
src/libnmc-base/nm-vpn-helpers.c
src/libnmc-setting/nm-meta-setting-access.c
src/libnmc-setting/nm-meta-setting-desc.c
src/libnmc-setting/nm-meta-setting-desc.h
src/libnmc-setting/settings-docs.h.in
src/libnmt-newt/nmt-newt-utils.c
src/nm-online/nm-online.c
src/nmcli/agent.c
src/nmcli/common.c
src/nmcli/connections.c
src/nmcli/devices.c
src/nmcli/general.c
src/nmcli/nmcli.c
src/nmcli/polkit-agent.c
src/nmcli/settings.c
src/nmcli/utils.c
src/nmcli/utils.h
src/nmtui/nm-editor-utils.c
src/nmtui/nmt-8021x-fields.c
src/nmtui/nmt-connect-connection-list.c
src/nmtui/nmt-device-entry.c
src/nmtui/nmt-edit-connection-list.c
src/nmtui/nmt-editor-section.c
src/nmtui/nmt-editor.c
src/nmtui/nmt-mtu-entry.c
src/nmtui/nmt-page-bond-port.c
src/nmtui/nmt-page-bond.c
src/nmtui/nmt-page-bridge-port.c
src/nmtui/nmt-page-bridge.c
src/nmtui/nmt-page-dsl.c
src/nmtui/nmt-page-ethernet.c
src/nmtui/nmt-page-infiniband.c
src/nmtui/nmt-page-ip-tunnel.c
src/nmtui/nmt-page-ip4.c
src/nmtui/nmt-page-ip6.c
src/nmtui/nmt-page-loopback.c
src/nmtui/nmt-page-macsec.c
src/nmtui/nmt-page-ppp.c
src/nmtui/nmt-page-team-port.c
src/nmtui/nmt-page-team.c
src/nmtui/nmt-page-veth.c
src/nmtui/nmt-page-vlan.c
src/nmtui/nmt-page-wifi.c
src/nmtui/nmt-page-wireguard.c
src/nmtui/nmt-password-dialog.c
src/nmtui/nmt-password-fields.c
src/nmtui/nmt-port-list.c
src/nmtui/nmt-route-editor.c
src/nmtui/nmt-route-table.c
src/nmtui/nmt-widget-list.c
src/nmtui/nmt-wireguard-peer-editor.c
src/nmtui/nmt-wireguard-peer-list.c
src/nmtui/nmtui-connect.c
src/nmtui/nmtui-edit.c
src/nmtui/nmtui-hostname.c
src/nmtui/nmtui-radio.c
src/nmtui/nmtui.c