#34 Replace firewall-config with plasma-firewall
Opened by ngompa. Modified

Now with Plasma 5.21, there is a new Plasma Firewall application to configure FirewallD. We should switch from the firewall-config GTK application to Plasma Firewall.

Source: https://invent.kde.org/network/plasma-firewall


I think we need to actually see and test the application before making any changes.
In particular, it would appear to have some serious shortcomings, especially with respect to recently introduced support for firewalld :
https://invent.kde.org/network/plasma-firewall/-/issues/16

lacking support for firewalld zones may be a deal-breaker. But, I'll reserve final judgement until there's something to test.

Metadata Update from @ngompa:
- Issue tagged with: meeting-request

@apol, @ngraham: Is there any chance we could get the Plasma Firewall developer(s) to join us in the SIG meeting next Monday (as that's the KDE<->Fedora sync meeting)? We'd like to discuss using Plasma Firewall for our FirewallD frontend with them.

Yep, he'll be joining next week. I can too.

Putting this on next week's agenda then.

Metadata Update from @ngompa:
- Issue untagged with: meeting-request
- Issue tagged with: meeting

Looks like firewalld interfaces all require privilege. Not a problem for firewall-config since it essentially runs as root.
for org.fedoraproject.FirewallD1 dbus, we can write some policykit rules for access. In particular, a a first step would be to allow local users read access, and admin users write access.
The first question, was how to query firewalld vesion, command line variant:
qdbus-qt5 --system org.fedoraproject.FirewallD1 /org/fedoraproject/FirewallD1 org.fedoraproject.FirewallD1.version

@rdieter Did you contact Tomaz and work out the remaining effort here?

Metadata Update from @ngompa:
- Issue assigned to rdieter

No, I thought my only task was to work on the policykit conf, sorry

I reached out to Tomaz but did not get a reply yet. Pinged him.

Metadata Update from @ngompa:
- Issue untagged with: meeting
- Issue set to the milestone: Fedora 35 (was: Fedora 34)

We're basically out of time for making this change for Fedora 34, so we're going to defer this for Fedora 35. Regardless, it'll be in the repositories for folks to try and use.

FYI new source is https://invent.kde.org/plasma/plasma-firewall.

Btw what were the summarized steps left?
PolicyKit
Anything else?
Firewall Zones: https://invent.kde.org/plasma/plasma-firewall/-/issues/16 << Tracking Issue

PR to add polkit rule to firewalld allowing use by "admin" users
https://src.fedoraproject.org/rpms/firewalld/pull-request/7

firewalld zones tracking issue moved to https://bugs.kde.org/show_bug.cgi?id=434954

cc: @ngraham who filed #72 (which is a dupe of this ticket).

Metadata Update from @ngompa:
- Issue unmarked as blocking: #72

lol so I did

We're waiting for zone support...

Metadata Update from @ngompa:
- Issue set to the milestone: Fedora 36 (was: Fedora 35)

Metadata Update from @ngompa:
- Issue set to the milestone: Fedora Linux 36 (was: Fedora 36)

Metadata Update from @siosm:
- Issue tagged with: packaging

Metadata Update from @siosm:
- Issue untagged with: packaging

Metadata Update from @siosm:
- Issue tagged with: packaging

Is there any updates on this worth mentioning?

Metadata Update from @timaeos:
- Issue set to the milestone: Future Release (was: Fedora Linux 36)

Is there any updates on this worth mentioning?

Negative, the person that was working on implementing zone support upstream doesn't appear to be working on this anymore. It would need developer resources to get the upstream support added.

Metadata Update from @timaeos:
- Assignee reset

Metadata Update from @timaeos:
- Issue tagged with: need-work

Metadata