Scope asdcontrol's passwordless sudo grant (#242)
Ship the least-privilege rule with asdcontrol so authorization follows the package lifecycle. Install it after older broad rules for safe staggered upgrades.
This commit is contained in:
@@ -2,7 +2,7 @@
|
||||
pkgname=asdcontrol
|
||||
epoch=1
|
||||
pkgver=0.6.0
|
||||
pkgrel=1
|
||||
pkgrel=2
|
||||
pkgdesc="Control brightness on Apple Displays connected via USB-C"
|
||||
arch=('x86_64')
|
||||
url="https://github.com/omakasui/asdcontrol"
|
||||
@@ -10,9 +10,14 @@ license=('GPL2')
|
||||
options=('!debug')
|
||||
depends=('glibc' 'gcc-libs')
|
||||
makedepends=('make' 'gcc')
|
||||
source=("$pkgname-$pkgver.tar.gz::https://github.com/omakasui/asdcontrol/archive/refs/tags/v$pkgver.tar.gz")
|
||||
sha256sums=('3112a6d5fc51a204c96ef9d27187577c6efc80b952e37a77969efbd0124e81d3')
|
||||
install=asdcontrol.install
|
||||
source=(
|
||||
"$pkgname-$pkgver.tar.gz::https://github.com/omakasui/asdcontrol/archive/refs/tags/v$pkgver.tar.gz"
|
||||
'asdcontrol.sudoers'
|
||||
)
|
||||
sha256sums=(
|
||||
'3112a6d5fc51a204c96ef9d27187577c6efc80b952e37a77969efbd0124e81d3'
|
||||
'dff3a5ecbe77825b4ea82235d5fd8589832a0462108ab573140488ae54989d23'
|
||||
)
|
||||
|
||||
build() {
|
||||
cd "$srcdir/asdcontrol-$pkgver"
|
||||
@@ -22,11 +27,7 @@ build() {
|
||||
package() {
|
||||
cd "$srcdir/asdcontrol-$pkgver"
|
||||
|
||||
# Install the binary
|
||||
install -Dm755 asdcontrol "$pkgdir/usr/bin/asdcontrol"
|
||||
|
||||
# Install the sudoers file for passwordless execution
|
||||
install -dm750 "$pkgdir/etc/sudoers.d"
|
||||
echo "ALL ALL=(ALL) NOPASSWD: /usr/bin/asdcontrol" > "$pkgdir/etc/sudoers.d/asdcontrol"
|
||||
chmod 440 "$pkgdir/etc/sudoers.d/asdcontrol"
|
||||
install -m440 "$srcdir/asdcontrol.sudoers" "$pkgdir/etc/sudoers.d/zz-asdcontrol"
|
||||
}
|
||||
|
||||
@@ -1,13 +0,0 @@
|
||||
post_install() {
|
||||
echo ":: asdcontrol has been installed"
|
||||
echo ":: You can now use 'sudo asdcontrol' to control Apple Display brightness"
|
||||
echo ":: Passwordless sudo has been configured for /usr/bin/asdcontrol"
|
||||
}
|
||||
|
||||
post_upgrade() {
|
||||
post_install
|
||||
}
|
||||
|
||||
post_remove() {
|
||||
echo ":: Sudoers configuration for asdcontrol has been removed"
|
||||
}
|
||||
@@ -0,0 +1,4 @@
|
||||
# Deny arbitrary asdcontrol arguments before allowing only the operations Omarchy uses.
|
||||
# Keep this filename late-sorting so it also overrides stale broader grants.
|
||||
ALL ALL=(ALL) !/usr/bin/asdcontrol
|
||||
%wheel ALL=(root) NOPASSWD: /usr/bin/asdcontrol ^--detect (/dev/(usb/)?hiddev[0-9]+)( /dev/(usb/)?hiddev[0-9]+)*$, /usr/bin/asdcontrol ^/dev/(usb/)?hiddev[0-9]+$, /usr/bin/asdcontrol ^/dev/(usb/)?hiddev[0-9]+ -- [+-]?[0-9]{1,3}%$
|
||||
Reference in New Issue
Block a user