aboutsummaryrefslogtreecommitdiff
path: root/modules/system/nixos/polkit.nix
diff options
context:
space:
mode:
authorCollin Williams <96917990+bluedragon1221@users.noreply.github.com>2026-01-29 20:15:19 -0600
committerCollin Williams <96917990+bluedragon1221@users.noreply.github.com>2026-01-30 08:38:21 -0600
commitc9a1d2da80bca0a85e8c18f6d2db71c4d1127eda (patch)
tree9da79e318ff0533a3708aee85a0b6a6d7f1d1036 /modules/system/nixos/polkit.nix
parentc81952cbcb6c6f1b41c2b6e2a366891991cceaee (diff)
Spring Cleaning
- create new module, `system`, that consumes the `boot` module and takes in the more system-interested services from the `services` module - touch up left over services (which are more self-hosting interested) - touch up yo and yoshi configs
Diffstat (limited to 'modules/system/nixos/polkit.nix')
-rw-r--r--modules/system/nixos/polkit.nix75
1 files changed, 75 insertions, 0 deletions
diff --git a/modules/system/nixos/polkit.nix b/modules/system/nixos/polkit.nix
new file mode 100644
index 0000000..29a06f4
--- /dev/null
+++ b/modules/system/nixos/polkit.nix
@@ -0,0 +1,75 @@
+{lib, ...}: let
+ defaultDenyRule = ''
+ polkit.addRule(function(action, subject) {
+ // Log denied actions for debugging
+ polkit.log("DENY: action=" + action.id + " user=" + subject.user);
+ return polkit.Result.NO;
+ });
+ '';
+
+ run0Rules = ''
+ polkit.addRule(function(action, subject) {
+ if (subject.isInGroup("wheel") && action.id === "org.freedesktop.systemd1.manage-units") {
+ return polkit.Result.AUTH_ADMIN_KEEP;
+ }
+ });
+ '';
+
+ networkRules = ''
+ polkit.addRule(function(action, subject) {
+ // Only allow network modifications for wheel group (admins)
+ if (action.id.startsWith("org.freedesktop.NetworkManager.") &&
+ subject.isInGroup("wheel")) {
+ return polkit.Result.YES;
+ }
+
+ // Allow reading network status for all users
+ if (action.id == "org.freedesktop.NetworkManager.network-control" ||
+ action.id == "org.freedesktop.NetworkManager.settings.modify.system") {
+ if (subject.isInGroup("wheel")) {
+ return polkit.Result.YES;
+ }
+ return polkit.Result.NO;
+ }
+
+ return polkit.Result.NOT_HANDLED;
+ });
+ '';
+
+ powerRules = ''
+ polkit.addRule(function(action, subject) {
+ if (action.id.match("org.freedesktop.login1.")) {
+ return polkit.Result.YES;
+ }
+ });
+ '';
+
+ bluetoothRules = ''
+ polkit.addRule(function(action, subject) {
+ // Allow users to manage bluetooth devices
+ if (action.id.startsWith("org.bluez.") &&
+ subject.local && subject.active) {
+ return polkit.Result.YES;
+ }
+
+ return polkit.Result.NOT_HANDLED;
+ });
+ '';
+in {
+ security = {
+ polkit = {
+ enable = true;
+ adminIdentities = ["unix-group:wheel"];
+
+ extraConfig = lib.concatStringsSep "\n\n" [
+ run0Rules
+ networkRules
+ powerRules
+ bluetoothRules
+ defaultDenyRule
+ ];
+ };
+
+ soteria.enable = true;
+ };
+}