Skip to content

engineering: Add permissions for LG#38

Merged
ayaegashi merged 3 commits into
mainfrom
ayaegashi/lgselinux
Jul 25, 2025
Merged

engineering: Add permissions for LG#38
ayaegashi merged 3 commits into
mainfrom
ayaegashi/lgselinux

Conversation

@ayaegashi
Copy link
Copy Markdown
Contributor

🔍 Description

This PR gives permission to Trident to copy SSH keys, which is required for a LG user script.

@ayaegashi ayaegashi requested a review from a team as a code owner July 21, 2025 15:47
jiria
jiria previously approved these changes Jul 21, 2025
@ayaegashi ayaegashi dismissed stale reviews from alejandro-microsoft and jiria via 3fbf82c July 21, 2025 18:48
Comment thread selinux-policy-trident/trident.te Outdated
@ayaegashi ayaegashi changed the title engineering: Add permissions for LG DNM engineering: Add permissions for LG Jul 23, 2025
@ayaegashi ayaegashi changed the title DNM engineering: Add permissions for LG engineering: Add permissions for LG Jul 25, 2025
@ayaegashi ayaegashi merged commit f4351e3 into main Jul 25, 2025
9 checks passed
alejandro-microsoft pushed a commit that referenced this pull request Aug 4, 2025
* LG denial

* trident module to permissive

* remove permissie statement
@ayaegashi ayaegashi deleted the ayaegashi/lgselinux branch August 27, 2025 01:33
bfjelds added a commit that referenced this pull request May 25, 2026
Fixes from frhuelsz code review:

- grub_cfg: skip $variable references during partition extraction (#30)
- users: use * lock marker instead of ! for AZL UsePAM=no (#31)
- users: fsync + parent dir sync in atomic_write_file (#33)
- users: propagate unexpected errors from check_user_exists (#36)
- users: explicitly lock new users when no password set (#43)
- users: skip set_primary_group for new users (useradd -g suffices) (#46)
- users: named constants for shadow/passwd field indices (#41)
- users: named constants for SSH dir/file permissions (#52)
- config: add deny_unknown_fields to remaining serde structs (#38)
- config: doc comment on PasswordType intentional reduction (#37)
- services: error on non-UTF-8 root path instead of silent fallback (#51)
- modules: document intentional Disable fidelity fix vs Go (#50)
- selinux: doc comment clarifying non-overlapping call paths (#45)
- lib: update OsModifierContext doc for MOS config path (#54)
- lib: add caller invariant doc on modify_os for UKI (#32)
- lib: add BootTarget enum note for future UKI-awareness (#53)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants