|
|
8631a2 |
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
|
|
|
8631a2 |
From: Hans de Goede <hdegoede@redhat.com>
|
|
|
8631a2 |
Date: Fri, 14 Sep 2018 16:39:40 +0200
|
|
|
8631a2 |
Subject: [PATCH] docs: Stop using polkit / pkexec for grub-boot-success.timer
|
|
|
8631a2 |
/ service
|
|
|
8631a2 |
|
|
|
8631a2 |
We also want to call grub2-set-bootflag under gdm and pkexec does not
|
|
|
8631a2 |
work under gdm because the gdm user has /sbin/nologin as shell.
|
|
|
8631a2 |
|
|
|
8631a2 |
So instead we are going to install grub2-set-bootflag as suid root,
|
|
|
8631a2 |
grub2-set-bootflag was written with this usage in mind, so is safe
|
|
|
8631a2 |
to be made suid root.
|
|
|
8631a2 |
|
|
|
8631a2 |
Signed-off-by: Hans de Goede <hdegoede@redhat.com>
|
|
|
8631a2 |
---
|
|
|
030dc3 |
docs/grub-boot-success.service | 2 +-
|
|
|
030dc3 |
docs/grub-boot-success.timer | 1 -
|
|
|
030dc3 |
docs/org.gnu.grub.policy | 20 --------------------
|
|
|
030dc3 |
3 files changed, 1 insertion(+), 22 deletions(-)
|
|
|
030dc3 |
delete mode 100644 docs/org.gnu.grub.policy
|
|
|
8631a2 |
|
|
|
030dc3 |
diff --git a/docs/grub-boot-success.service b/docs/grub-boot-success.service
|
|
|
030dc3 |
index c8c91c34d49..80e79584c91 100644
|
|
|
030dc3 |
--- a/docs/grub-boot-success.service
|
|
|
030dc3 |
+++ b/docs/grub-boot-success.service
|
|
|
030dc3 |
@@ -3,4 +3,4 @@ Description=Mark boot as successful
|
|
|
030dc3 |
|
|
|
030dc3 |
[Service]
|
|
|
030dc3 |
Type=oneshot
|
|
|
030dc3 |
-ExecStart=/usr/bin/pkexec /usr/sbin/grub2-set-bootflag boot_success
|
|
|
030dc3 |
+ExecStart=/usr/sbin/grub2-set-bootflag boot_success
|
|
|
8631a2 |
diff --git a/docs/grub-boot-success.timer b/docs/grub-boot-success.timer
|
|
|
030dc3 |
index 67bd829b795..5d8fcba21aa 100644
|
|
|
8631a2 |
--- a/docs/grub-boot-success.timer
|
|
|
8631a2 |
+++ b/docs/grub-boot-success.timer
|
|
|
030dc3 |
@@ -1,7 +1,6 @@
|
|
|
030dc3 |
[Unit]
|
|
|
8631a2 |
Description=Mark boot as successful after the user session has run 2 minutes
|
|
|
8631a2 |
ConditionUser=!@system
|
|
|
8631a2 |
-ConditionPathExists=/usr/bin/pkexec
|
|
|
8631a2 |
|
|
|
8631a2 |
[Timer]
|
|
|
8631a2 |
OnActiveSec=2min
|
|
|
030dc3 |
diff --git a/docs/org.gnu.grub.policy b/docs/org.gnu.grub.policy
|
|
|
030dc3 |
deleted file mode 100644
|
|
|
030dc3 |
index 18391efc8e7..00000000000
|
|
|
030dc3 |
--- a/docs/org.gnu.grub.policy
|
|
|
030dc3 |
+++ /dev/null
|
|
|
030dc3 |
@@ -1,20 +0,0 @@
|
|
|
030dc3 |
-
|
|
|
030dc3 |
-
|
|
|
030dc3 |
-<policyconfig>
|
|
|
030dc3 |
- <vendor>GNU GRUB</vendor>
|
|
|
030dc3 |
- <vendor_url>https://www.gnu.org/software/grub/</vendor_url>
|
|
|
030dc3 |
- <action id="org.gnu.grub.set-bootflag">
|
|
|
030dc3 |
-
|
|
|
030dc3 |
- - A normal active user on the local machine does not need permission
|
|
|
030dc3 |
- to set bootflags to show the menu / mark current boot successful.
|
|
|
030dc3 |
- -->
|
|
|
030dc3 |
- <description>Set GRUB bootflags</description>
|
|
|
030dc3 |
- <message>Authentication is required to modify the bootloaders bootflags</message>
|
|
|
030dc3 |
- <defaults>
|
|
|
030dc3 |
- <allow_any>no</allow_any>
|
|
|
030dc3 |
- <allow_inactive>no</allow_inactive>
|
|
|
030dc3 |
- <allow_active>yes</allow_active>
|
|
|
030dc3 |
- </defaults>
|
|
|
030dc3 |
- <annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/grub2-set-bootflag</annotate>
|
|
|
030dc3 |
- </action>
|
|
|
030dc3 |
-</policyconfig>
|