-
-
Notifications
You must be signed in to change notification settings - Fork 481
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Document /run/qubes/policy.d/
#1427
base: main
Are you sure you want to change the base?
Conversation
Useful for users of the feature.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Some nitpicks, not blockers.
Code PR was merged recently.
@@ -112,6 +113,10 @@ In the target VM, a file in either of the following locations must exist, contai | |||
- `/etc/qubes-rpc/RPC_ACTION_NAME` when you make it in the template qube; | |||
- `/usr/local/etc/qubes-rpc/RPC_ACTION_NAME` for making it only in an app qube. | |||
|
|||
Files in `/run/qubes/policy.d/` are deleted when the system is rebooted. | |||
This is useful for temporary policy that contains the name or UUID of a disposable VM, which will not be meaningful after the system has rebooted. | |||
Such policy files can be created manually, but they are usually created automatically by a qrexec call to dom0. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Qrexec should be capitalized as it refers to the protocol and not to program (e.g. qrexec-client-vm).
@@ -86,11 +86,12 @@ Disposable VMs are tightly integrated -- RPC to a DisposableVM is identical to R | |||
|
|||
### Policy files | |||
|
|||
The dom0 directory `/etc/qubes/policy.d/` contains files that set policy for each available RPC action that a VM might call. | |||
The dom0 directories `/etc/qubes/policy.d/` and `/run/qubes/policy.d/` contain files that set policy for each available RPC action that a VM might call. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
s/VM/qube/
, but then there are other places on this file to change it.
Useful for users of the feature.