"foo $anyvm deny" policy overrides previous lines #4403
Labels
C: doc
P: default
Priority: default. Default priority for new issues, to be replaced given sufficient information.
T: enhancement
Type: enhancement. A new feature that does not yet exist or improvement of existing functionality.
Milestone
Qubes OS version:
R4.0 (I installed updates in templates and for dom0 a few days ago and rebooted, but the issue persists)
Affected component(s):
Policy for qubes.Filecopy (I didn't try other policies)
Steps to reproduce the behavior:
In
dom0
, have the following policies forqubes.Filecopy
:In VM
foo
, run:Expected behavior:
The confirmation dialog for
qubes.Filecopy
should pop up, listing onlybar
as a possible destination.Actual behavior:
The
qvm-copy example-file
operation fails withRequest refused
General notes:
If the policy line
foo $anyvm deny
is commented out, the confirmation dialog pops up as expected. It containsbar
and other VMs, but correctly omitsquux
. Thedeny
mechanism therefore works, but it seems that thefoo $anyvm deny
line overrides the previous lines.The documentation at https://www.qubes-os.org/doc/rpc-policy/ and the comments at the top of
/etc/qubes-rpc/policy/qubes.Filecopy
indicate that lines at the top of the file have precedence over the lines below.Related issues:
The text was updated successfully, but these errors were encountered: