From 95c75badd5617c5e1a905938c1d7c725dfcb298b Mon Sep 17 00:00:00 2001 From: xavierk Date: Tue, 15 Sep 2026 15:44:10 +0530 Subject: [PATCH] Route TUI controls through polkit --- src/fenris/tui.py | 3 +++ tests/test_tui.py | 16 ++++++++++++++++ 2 files changed, 19 insertions(+) diff --git a/src/fenris/tui.py b/src/fenris/tui.py index 23d8e60..d2a2724 100644 --- a/src/fenris/tui.py +++ b/src/fenris/tui.py @@ -14,6 +14,7 @@ Criteria: TUI-1, TUI-2, TUI-4, CI-1, CI-2, CI-4, IN-3, LC-6, LC-8. """ from __future__ import annotations +import os import sqlite3 import subprocess import sys @@ -1454,6 +1455,8 @@ class FenrisTuiApp(App): cmd = [self.helper_path, operation] if extra_args: cmd.extend(extra_args) + if os.geteuid() != 0: + cmd.insert(0, "pkexec") try: with self.suspend(): diff --git a/tests/test_tui.py b/tests/test_tui.py index 603e5fb..8b94f4e 100644 --- a/tests/test_tui.py +++ b/tests/test_tui.py @@ -595,6 +595,22 @@ class TestDisclosuresAndGreeting: # --------------------------------------------------------------------------- class TestFirstRun: + def test_unprivileged_resume_uses_polkit(self, tmp_path): + """TUI controls use the same authenticated path as the CLI.""" + app = FenrisTuiApp(store_path=tmp_path / "nonexistent.db") + + with patch("fenris.tui.os.geteuid", return_value=1000), \ + patch("fenris.tui.subprocess.run") as run, \ + patch.object(app, "suspend"), \ + patch.object(app, "_refresh"): + run.return_value.returncode = 0 + app._run_helper("enable", ["--now"]) + + run.assert_called_once_with( + ["pkexec", "/usr/libexec/fenris/fenris-monitor", "enable", "--now"], + timeout=30, + ) + @pytest.mark.asyncio async def test_first_run_prompt(self, tmp_path): """First-run prompt makes the keyboard action and boot effect explicit."""