mirror of
https://github.com/troglobit/finit.git
synced 2026-10-01 05:22:48 +07:00
It still described treating every system-bus caller as unprivileged as the state of things, which stopped being true when Finit learned to ask the broker who sent a call. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
64 lines
2.3 KiB
XML
64 lines
2.3 KiB
XML
<?xml version="1.0" encoding="UTF-8"?>
|
|
<!DOCTYPE busconfig PUBLIC
|
|
"-//freedesktop//DTD D-BUS Bus Configuration 1.0//EN"
|
|
"http://www.freedesktop.org/standards/dbus/1.0/busconfig.dtd">
|
|
<!--
|
|
System-bus policy for finit.
|
|
|
|
finit (PID 1, root) owns the `org.finit` well-known name. The
|
|
policy below lets unprivileged callers introspect, read
|
|
properties, and query service / condition state, but disallows
|
|
every state-changing method at the broker. finit *also* enforces
|
|
per-method authorisation itself (LINK_METHOD_PRIVILEGED), so
|
|
defense-in-depth: even if a permissive policy is installed by
|
|
mistake, finit rejects unprivileged state changes. It reads the
|
|
caller from SO_PEERCRED on the local bus, and on the system bus it
|
|
asks the broker who sent each privileged call, via
|
|
GetConnectionUnixUser.
|
|
-->
|
|
<busconfig>
|
|
|
|
<!-- Only finit (root) may own the org.finit bus name. -->
|
|
<policy user="root">
|
|
<allow own="org.finit"/>
|
|
<allow send_destination="org.finit"/>
|
|
<allow receive_sender="org.finit"/>
|
|
</policy>
|
|
|
|
<!-- Everyone may introspect, read properties, and call the
|
|
read-only Manager1 / Cond1 methods. Signals fan out
|
|
unconditionally. -->
|
|
<policy context="default">
|
|
<allow send_destination="org.finit"
|
|
send_interface="org.freedesktop.DBus.Introspectable"/>
|
|
<allow send_destination="org.finit"
|
|
send_interface="org.freedesktop.DBus.Peer"/>
|
|
<allow send_destination="org.finit"
|
|
send_interface="org.freedesktop.DBus.Properties"
|
|
send_member="Get"/>
|
|
<allow send_destination="org.finit"
|
|
send_interface="org.freedesktop.DBus.Properties"
|
|
send_member="GetAll"/>
|
|
|
|
<allow send_destination="org.finit"
|
|
send_interface="org.finit.Manager1"
|
|
send_member="ListServices"/>
|
|
<allow send_destination="org.finit"
|
|
send_interface="org.finit.Manager1"
|
|
send_member="GetService"/>
|
|
|
|
<allow send_destination="org.finit"
|
|
send_interface="org.finit.Cond1"
|
|
send_member="Get"/>
|
|
<allow send_destination="org.finit"
|
|
send_interface="org.finit.Cond1"
|
|
send_member="List"/>
|
|
<allow send_destination="org.finit"
|
|
send_interface="org.finit.Cond1"
|
|
send_member="Dump"/>
|
|
|
|
<allow receive_sender="org.finit"/>
|
|
</policy>
|
|
|
|
</busconfig>
|