aboutsummaryrefslogtreecommitdiffstatshomepage
path: root/run_onchange_after_deploy-thunderbird.sh.tmpl
diff options
context:
space:
mode:
authorLibravatar sommerfeld <sommerfeld@sommerfeld.dev>2026-05-29 11:18:12 +0100
committerLibravatar sommerfeld <sommerfeld@sommerfeld.dev>2026-05-29 11:18:12 +0100
commitcdf6350a7ad530feee509c63675ff6cc74cb7ced (patch)
treed5e39199a47a4b4b9c30e3e9b2c1065f4896ce55 /run_onchange_after_deploy-thunderbird.sh.tmpl
parent75e84558ea71f14adbaa1a461cd5f6e8793b0470 (diff)
downloaddotfiles-cdf6350a7ad530feee509c63675ff6cc74cb7ced.tar.gz
dotfiles-cdf6350a7ad530feee509c63675ff6cc74cb7ced.tar.bz2
dotfiles-cdf6350a7ad530feee509c63675ff6cc74cb7ced.zip
feat(polkit): restrict systemd + udisks system actions to active local sessions
Two narrow defence-in-depth rules: - 52-systemd-local-only: org.freedesktop.systemd1.* requires both subject.local and subject.active. Wheel-via-sudo-rs is on a different path (sudoers) and is not affected. Stops a non-active or remote polkit caller from start/stop/restart of system units. - 53-udisks-system-mount: filesystem-mount-system and modify-system require subject.active. The everyday USB auto-mount path uses filesystem-mount (no -system suffix) and is unaffected. Audited against current workflow (virt-manager, networkctl, USB mount, bluetoothctl, fwupdmgr) — none of these break.
Diffstat (limited to 'run_onchange_after_deploy-thunderbird.sh.tmpl')
0 files changed, 0 insertions, 0 deletions