feat(releng): add polkit policy for fws-recovery privileged operations

Add PolicyKit authorization policy file to allow fws-recovery-gui to execute fws-recovery engine via pkexec with administrative privileges. The policy uses auth_admin_keep to require authentication only once per session.
This commit is contained in:
2026-07-07 02:48:03 +02:00
parent 9e3a02d96d
commit de05361b28
@@ -0,0 +1,26 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE policyconfig PUBLIC
"-//freedesktop//DTD PolicyKit Policy Configuration 1.0//EN"
"http://www.freedesktop.org/standards/PolicyKit/1.0/policyconfig.dtd">
<!--
FWS — autorise fws-recovery-gui (lancée en utilisateur depuis le menu de
l'OS installé) à exécuter le MOTEUR fws-recovery via pkexec.
auth_admin_keep : le mot de passe administrateur n'est demandé qu'une fois
(mémorisé quelques minutes), pas à chaque bouton.
-->
<policyconfig>
<vendor>FWS</vendor>
<action id="org.fws.recovery">
<description>Réparer le système FWS</description>
<description xml:lang="en">Repair the FWS system</description>
<message>Authentification requise pour réparer le système</message>
<message xml:lang="en">Authentication is required to repair the system</message>
<icon_name>fws-recovery</icon_name>
<defaults>
<allow_any>auth_admin_keep</allow_any>
<allow_inactive>auth_admin_keep</allow_inactive>
<allow_active>auth_admin_keep</allow_active>
</defaults>
<annotate key="org.freedesktop.policykit.exec.path">/usr/local/bin/fws-recovery</annotate>
</action>
</policyconfig>