From 99fb13856c9f1067b714ca0ca368129741847540 Mon Sep 17 00:00:00 2001 From: Ben Grande Date: Wed, 19 Jun 2024 15:11:43 +0200 Subject: [PATCH] fix: correct git repository name in policy --- .../files/admin/policy/default.policy | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/salt/qubes-builder/files/admin/policy/default.policy b/salt/qubes-builder/files/admin/policy/default.policy index fbd9e1d..1081e59 100644 --- a/salt/qubes-builder/files/admin/policy/default.policy +++ b/salt/qubes-builder/files/admin/policy/default.policy @@ -8,9 +8,9 @@ qubes.Gpg2 * {{ sls_path }} @default allow target=sys-pgp qubes.Gpg2 * {{ sls_path }} @anyvm deny -qusal.GitInit +qubes-builder {{ sls_path }} @default allow target=sys-git -qusal.GitFetch +qubes-builder {{ sls_path }} @default allow target=sys-git -qusal.GitPush +qubes-builder {{ sls_path }} @default ask target=sys-git default_target=sys-git +qusal.GitInit +qubes-builderv2 {{ sls_path }} @default allow target=sys-git +qusal.GitFetch +qubes-builderv2 {{ sls_path }} @default allow target=sys-git +qusal.GitPush +qubes-builderv2 {{ sls_path }} @default ask target=sys-git default_target=sys-git qusal.SshAgent +qubes-builder {{ sls_path }} @default allow target=sys-ssh-agent qusal.SshAgent +qubes-builder {{ sls_path }} @anyvm deny @@ -18,12 +18,12 @@ qusal.SshAgent +qubes-builder {{ sls_path }} @anyvm deny admin.vm.CreateDisposable * {{ sls_path }} dom0 allow admin.vm.CreateDisposable * {{ sls_path }} dvm-qubes-builder allow target=dom0 admin.vm.Start * {{ sls_path }} @tag:disp-created-by-{{ sls_path }} allow target=dom0 -admin.vm.Kill * {{ sls_path }} @tag:disp-created-by-{{ sls_path }} allow target=dom0 +admin.vm.Kill * {{ sls_path }} @tag:disp-created-by-{{ sls_path }} allow target=dom0 -qubesbuilder.FileCopyIn * {{ sls_path }} @tag:disp-created-by-{{ sls_path }} allow +qubesbuilder.FileCopyIn * {{ sls_path }} @tag:disp-created-by-{{ sls_path }} allow qubesbuilder.FileCopyOut * {{ sls_path }} @tag:disp-created-by-{{ sls_path }} allow -qubes.Filecopy * {{ sls_path }} @tag:disp-created-by-{{ sls_path }} allow +qubes.Filecopy * {{ sls_path }} @tag:disp-created-by-{{ sls_path }} allow qubes.WaitForSession * {{ sls_path }} @tag:disp-created-by-{{ sls_path }} allow -qubes.VMShell * {{ sls_path }} @tag:disp-created-by-{{ sls_path }} allow +qubes.VMShell * {{ sls_path }} @tag:disp-created-by-{{ sls_path }} allow ## vim:ft=qrexecpolicy