dbus: install the bus policy in $datadir/dbus-1/system.d

make distcheck fails in install:

    /usr/bin/install: cannot create regular file '/etc/dbus-1/system.d/org.finit.conf': Permission denied

The policy was installed to $sysconfdir/dbus-1/system.d.  distcheck only
overrides the prefix, so the file escaped its sandbox and aimed for the
real /etc.

Install it where dbus looks for package owned policy, leaving
/etc/dbus-1/system.d to the admin.  The test bus config reads it
relative to itself.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit is contained in:
Joachim Wiberg
2026-08-29 13:54:14 +02:00
parent 969f9a112c
commit 847f4db974
3 changed files with 8 additions and 4 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
EXTRA_DIST = org.finit.conf
if DBUS
dbuspolicydir = $(sysconfdir)/dbus-1/system.d
dbuspolicydir = $(datadir)/dbus-1/system.d
dist_dbuspolicy_DATA = org.finit.conf
endif
+3 -2
View File
@@ -43,8 +43,9 @@ connections are refused until one disconnects. Match rules given to
`arg0` and its variants are not implemented.
For the system bus a standard busconfig policy ships in
`dbus-1/org.finit.conf`: only root may own `org.finit`, unprivileged
callers reach introspection, properties, and the read-only methods.
`dbus-1/org.finit.conf`, installed to `$datadir/dbus-1/system.d`: only
root may own `org.finit`, unprivileged callers reach introspection,
properties, and the read-only methods.
Finit also enforces per-method authorization itself, so a permissive
policy installed by mistake does not open state-changing methods.
+4 -1
View File
@@ -16,7 +16,10 @@
<type>system</type>
<!-- Pick up the policy Finit itself ships, so a malformed
org.finit.conf fails the test rather than a target. -->
org.finit.conf fails the test rather than a target. The first
is relative to this file, i.e. where the install lands, the
second is the admin override directory. -->
<includedir>system.d</includedir>
<includedir>/etc/dbus-1/system.d</includedir>
<listen>unix:path=/var/run/dbus/system_bus_socket</listen>
<auth>EXTERNAL</auth>