Scope asdcontrol's passwordless sudo grant (#242)

Ship the least-privilege rule with asdcontrol so authorization follows the package lifecycle. Install it after older broad rules for safe staggered upgrades.
This commit is contained in:
Ryan Hughes
2026-08-30 12:59:21 -04:00
committed by GitHub
parent cf39173553
commit 30d03c4d26
3 changed files with 14 additions and 22 deletions
+10 -9
View File
@@ -2,7 +2,7 @@
pkgname=asdcontrol
epoch=1
pkgver=0.6.0
pkgrel=1
pkgrel=2
pkgdesc="Control brightness on Apple Displays connected via USB-C"
arch=('x86_64')
url="https://github.com/omakasui/asdcontrol"
@@ -10,9 +10,14 @@ license=('GPL2')
options=('!debug')
depends=('glibc' 'gcc-libs')
makedepends=('make' 'gcc')
source=("$pkgname-$pkgver.tar.gz::https://github.com/omakasui/asdcontrol/archive/refs/tags/v$pkgver.tar.gz")
sha256sums=('3112a6d5fc51a204c96ef9d27187577c6efc80b952e37a77969efbd0124e81d3')
install=asdcontrol.install
source=(
"$pkgname-$pkgver.tar.gz::https://github.com/omakasui/asdcontrol/archive/refs/tags/v$pkgver.tar.gz"
'asdcontrol.sudoers'
)
sha256sums=(
'3112a6d5fc51a204c96ef9d27187577c6efc80b952e37a77969efbd0124e81d3'
'dff3a5ecbe77825b4ea82235d5fd8589832a0462108ab573140488ae54989d23'
)
build() {
cd "$srcdir/asdcontrol-$pkgver"
@@ -22,11 +27,7 @@ build() {
package() {
cd "$srcdir/asdcontrol-$pkgver"
# Install the binary
install -Dm755 asdcontrol "$pkgdir/usr/bin/asdcontrol"
# Install the sudoers file for passwordless execution
install -dm750 "$pkgdir/etc/sudoers.d"
echo "ALL ALL=(ALL) NOPASSWD: /usr/bin/asdcontrol" > "$pkgdir/etc/sudoers.d/asdcontrol"
chmod 440 "$pkgdir/etc/sudoers.d/asdcontrol"
install -m440 "$srcdir/asdcontrol.sudoers" "$pkgdir/etc/sudoers.d/zz-asdcontrol"
}
-13
View File
@@ -1,13 +0,0 @@
post_install() {
echo ":: asdcontrol has been installed"
echo ":: You can now use 'sudo asdcontrol' to control Apple Display brightness"
echo ":: Passwordless sudo has been configured for /usr/bin/asdcontrol"
}
post_upgrade() {
post_install
}
post_remove() {
echo ":: Sudoers configuration for asdcontrol has been removed"
}
+4
View File
@@ -0,0 +1,4 @@
# Deny arbitrary asdcontrol arguments before allowing only the operations Omarchy uses.
# Keep this filename late-sorting so it also overrides stale broader grants.
ALL ALL=(ALL) !/usr/bin/asdcontrol
%wheel ALL=(root) NOPASSWD: /usr/bin/asdcontrol ^--detect (/dev/(usb/)?hiddev[0-9]+)( /dev/(usb/)?hiddev[0-9]+)*$, /usr/bin/asdcontrol ^/dev/(usb/)?hiddev[0-9]+$, /usr/bin/asdcontrol ^/dev/(usb/)?hiddev[0-9]+ -- [+-]?[0-9]{1,3}%$