Route TUI controls through polkit

This commit is contained in:
xavierk
2026-09-15 15:44:10 +05:30
parent 70dbae65fb
commit 95c75badd5
2 changed files with 19 additions and 0 deletions
+3
View File
@@ -14,6 +14,7 @@ Criteria: TUI-1, TUI-2, TUI-4, CI-1, CI-2, CI-4, IN-3, LC-6, LC-8.
""" """
from __future__ import annotations from __future__ import annotations
import os
import sqlite3 import sqlite3
import subprocess import subprocess
import sys import sys
@@ -1454,6 +1455,8 @@ class FenrisTuiApp(App):
cmd = [self.helper_path, operation] cmd = [self.helper_path, operation]
if extra_args: if extra_args:
cmd.extend(extra_args) cmd.extend(extra_args)
if os.geteuid() != 0:
cmd.insert(0, "pkexec")
try: try:
with self.suspend(): with self.suspend():
+16
View File
@@ -595,6 +595,22 @@ class TestDisclosuresAndGreeting:
# --------------------------------------------------------------------------- # ---------------------------------------------------------------------------
class TestFirstRun: class TestFirstRun:
def test_unprivileged_resume_uses_polkit(self, tmp_path):
"""TUI controls use the same authenticated path as the CLI."""
app = FenrisTuiApp(store_path=tmp_path / "nonexistent.db")
with patch("fenris.tui.os.geteuid", return_value=1000), \
patch("fenris.tui.subprocess.run") as run, \
patch.object(app, "suspend"), \
patch.object(app, "_refresh"):
run.return_value.returncode = 0
app._run_helper("enable", ["--now"])
run.assert_called_once_with(
["pkexec", "/usr/libexec/fenris/fenris-monitor", "enable", "--now"],
timeout=30,
)
@pytest.mark.asyncio @pytest.mark.asyncio
async def test_first_run_prompt(self, tmp_path): async def test_first_run_prompt(self, tmp_path):
"""First-run prompt makes the keyboard action and boot effect explicit.""" """First-run prompt makes the keyboard action and boot effect explicit."""