Allow users in the qubes group to access USBGuard IPC

This commit is contained in:
Aaron Rainbolt 2025-09-28 14:11:10 -05:00
parent 22c9863493
commit 7e016b5632
No known key found for this signature in database
GPG key ID: A709160D73C79109
3 changed files with 3 additions and 0 deletions

View file

@ -14,6 +14,7 @@ etc/apparmor.d/tunables/home.d/security-misc#security-misc-shared => /etc/apparm
etc/ssh/ssh_config.d/30_security-misc.conf#security-misc-shared => /etc/ssh/ssh_config.d/30_security-misc.conf
etc/ssh/sshd_config.d/30_security-misc.conf#security-misc-shared => /etc/ssh/sshd_config.d/30_security-misc.conf
etc/usbguard/IPCAccessControl.d/:sudo#security-misc-shared => /etc/usbguard/IPCAccessControl.d/:sudo
etc/usbguard/IPCAccessControl.d/:qubes#security-misc-shared => /etc/usbguard/IPCAccessControl.d/:qubes
etc/usbguard/rules.d/30_security-misc.conf#security-misc-shared => /etc/usbguard/rules.d/30_security-misc.conf
etc/usbguard/usbguard-daemon.conf.security-misc#security-misc-shared => /etc/usbguard/usbguard-daemon.conf.security-misc
etc/kernel/postinst.d/30_remove-system-map#security-misc-shared => /etc/kernel/postinst.d/30_remove-system-map

View file

@ -96,6 +96,7 @@ case "$1" in
'/etc/usbguard/rules.d/30_security-misc.conf'
'/etc/usbguard/usbguard-daemon.conf.security-misc'
'/etc/usbguard/IPCAccessControl.d/:sudo'
'/etc/usbguard/IPCAccessControl.d/:qubes'
)
for usbguard_config_file in "${usbguard_config_file_list[@]}"; do
if test -f "${usbguard_config_file}"; then