chiark / gitweb /
core: Verify systemd1 DBus method callers via polkit
[elogind.git] / src / core / org.freedesktop.systemd1.policy.in.in
1 <?xml version="1.0" encoding="UTF-8"?> <!--*-nxml-*-->
2 <!DOCTYPE policyconfig PUBLIC "-//freedesktop//DTD PolicyKit Policy Configuration 1.0//EN"
3         "http://www.freedesktop.org/standards/PolicyKit/1/policyconfig.dtd">
4
5 <!--
6   This file is part of systemd.
7
8   systemd is free software; you can redistribute it and/or modify it
9   under the terms of the GNU Lesser General Public License as published by
10   the Free Software Foundation; either version 2.1 of the License, or
11   (at your option) any later version.
12 -->
13
14 <policyconfig>
15
16         <vendor>The systemd Project</vendor>
17         <vendor_url>http://www.freedesktop.org/wiki/Software/systemd</vendor_url>
18
19         <action id="org.freedesktop.systemd1.reply-password">
20                 <_description>Send passphrase back to system</_description>
21                 <_message>Authentication is required to send the entered passphrase back to the system.</_message>
22                 <defaults>
23                         <allow_any>no</allow_any>
24                         <allow_inactive>no</allow_inactive>
25                         <allow_active>auth_admin_keep</allow_active>
26                 </defaults>
27                 <annotate key="org.freedesktop.policykit.exec.path">@rootlibexecdir@/systemd-reply-password</annotate>
28         </action>
29
30         <action id="org.freedesktop.systemd1.bus-access">
31                 <_description>Privileged system and service manager access</_description>
32                 <_message>Authentication is required to access the system and service manager.</_message>
33                 <defaults>
34                         <allow_any>no</allow_any>
35                         <allow_inactive>no</allow_inactive>
36                         <allow_active>auth_admin_keep</allow_active>
37                 </defaults>
38                 <annotate key="org.freedesktop.policykit.exec.path">@bindir@/systemd-stdio-bridge</annotate>
39         </action>
40
41         <action id="org.freedesktop.systemd1.manage-units">
42                 <_description>Manage system services or units</_description>
43                 <_message>Authentication is required to manage system services or units.</_message>
44                 <defaults>
45                         <allow_any>auth_admin</allow_any>
46                         <allow_inactive>auth_admin</allow_inactive>
47                         <allow_active>auth_admin_keep</allow_active>
48                 </defaults>
49         </action>
50
51         <action id="org.freedesktop.systemd1.manage-unit-files">
52                 <_description>Manage system service or unit files</_description>
53                 <_message>Authentication is required to manage system service or unit files.</_message>
54                 <defaults>
55                         <allow_any>auth_admin</allow_any>
56                         <allow_inactive>auth_admin</allow_inactive>
57                         <allow_active>auth_admin_keep</allow_active>
58                 </defaults>
59         </action>
60
61         <action id="org.freedesktop.systemd1.reload-daemon">
62                 <_description>Reload the systemd state</_description>
63                 <_message>Authentication is required to reload the systemd state.</_message>
64                 <defaults>
65                         <allow_any>auth_admin</allow_any>
66                         <allow_inactive>auth_admin</allow_inactive>
67                         <allow_active>auth_admin_keep</allow_active>
68                 </defaults>
69         </action>
70
71 </policyconfig>