Skip to content

Commit

Permalink
Use new policy location for sys-gui's Admin API settings
Browse files Browse the repository at this point in the history
  • Loading branch information
marmarek committed May 15, 2020
1 parent 24fd422 commit f484277
Showing 1 changed file with 11 additions and 11 deletions.
22 changes: 11 additions & 11 deletions qvm/template-gui.jinja
Original file line number Diff line number Diff line change
Expand Up @@ -23,31 +23,31 @@
# GuiVM (AdminVM) with local 'rwx' permissions
{{ vmname }}-admin-local-rwx:
file.append:
- name: /etc/qubes-rpc/policy/include/admin-local-rwx
- name: /etc/qubes/policy.d/include/admin-local-rwx
- text: |
{{ vmname }} @tag:guivm-{{ vmname }} allow,target=dom0
{{ vmname }} {{ vmname }} allow,target=dom0
{{ vmname }} @tag:guivm-{{ vmname }} allow target=dom0
{{ vmname }} {{ vmname }} allow target=dom0
# GuiVM (AdminVM) with global 'ro' permissions
{% if salt['pillar.get']('qvm:' + vmname + ':admin-global-permissions') == 'ro' %}
{{ vmname }}-admin-global-ro:
file.append:
- name: /etc/qubes-rpc/policy/include/admin-global-ro
- name: /etc/qubes/policy.d/include/admin-global-ro
- text: |
{{ vmname }} @adminvm allow,target=dom0
{{ vmname }} @tag:guivm-{{ vmname }} allow,target=dom0
{{ vmname }} {{ vmname }} allow,target=dom0
{{ vmname }} @adminvm allow target=dom0
{{ vmname }} @tag:guivm-{{ vmname }} allow target=dom0
{{ vmname }} {{ vmname }} allow target=dom0
{% endif %}

{% if salt['pillar.get']('qvm:' + vmname + ':admin-global-permissions') == 'rwx' %}
# GuiVM (AdminVM) with global 'rwx' permissions
{{ vmname }}-admin-global-rwx:
file.append:
- name: /etc/qubes-rpc/policy/include/admin-global-rwx
- name: /etc/qubes/policy.d/include/admin-global-rwx
- text: |
{{ vmname }} @adminvm allow,target=dom0
{{ vmname }} @tag:guivm-{{ vmname }} allow,target=dom0
{{ vmname }} {{ vmname }} allow,target=dom0
{{ vmname }} @adminvm allow target=dom0
{{ vmname }} @tag:guivm-{{ vmname }} allow target=dom0
{{ vmname }} {{ vmname }} allow target=dom0
{% endif %}
{%- endmacro %}

0 comments on commit f484277

Please sign in to comment.