fix(rdp): run grdctl --system directly as root, remove runuser/polkit/util-linux

Root cause: gnome-remote-desktop-setup.service ran as root but dropped
privileges via `runuser -u gnome-remote-desktop`. Non-root grdctl --system
attempts authorisation through pkexec. The Nix-store pkexec binary is not
setuid, so every system-mode credential call silently failed while the script
still printed "configured successfully". GNOME Remote Desktop then started
without applied credentials, causing Remmina to loop at the login dialog.

Fix:
- Remove `runuser -u gnome-remote-desktop --` from grdctl_system helper;
  the root-run oneshot service can call grdctl --system directly.
- Remove pkgs.polkit and pkgs.util-linux from the setup service path as
  neither polkit nor runuser is needed any more.
- Update tests: rename test_setup_runs_grdctl_as_gnome_remote_desktop_user
  to test_setup_runs_grdctl_directly_as_root and assert that runuser,
  pkexec, and sudo are absent; add
  test_privilege_escalation_packages_absent_from_setup_path.

All 21 app/tests pass.
This commit is contained in:
copilot-swe-agent[bot]
2026-07-14 00:28:17 +00:00
committed by GitHub
parent b4317c9589
commit fd5f651f2c
2 changed files with 10 additions and 5 deletions
+10 -2
View File
@@ -52,9 +52,17 @@ class RdpModuleBootSetupTests(unittest.TestCase):
self.assertIn('echo "grdctl command timed out: $*" >&2', self.setup_service) self.assertIn('echo "grdctl command timed out: $*" >&2', self.setup_service)
self.assertIn('echo "grdctl command failed (exit $rc): $*" >&2', self.setup_service) self.assertIn('echo "grdctl command failed (exit $rc): $*" >&2', self.setup_service)
def test_setup_runs_grdctl_as_gnome_remote_desktop_user(self): def test_setup_runs_grdctl_directly_as_root(self):
self.assertIn("runuser -u gnome-remote-desktop -- \\", self.setup_service) # The oneshot service already runs as root; system-mode grdctl must be
# invoked directly so it does not attempt pkexec authorisation.
self.assertIn('grdctl --system "$@"', self.setup_service) self.assertIn('grdctl --system "$@"', self.setup_service)
self.assertNotIn("runuser", self.setup_service)
self.assertNotIn("pkexec", self.setup_service)
self.assertNotIn("sudo", self.setup_service)
def test_privilege_escalation_packages_absent_from_setup_path(self):
self.assertNotIn("pkgs.polkit", self.setup_service)
self.assertNotIn("pkgs.util-linux", self.setup_service)
def test_hub_files_are_the_source_of_truth_for_username_and_password(self): def test_hub_files_are_the_source_of_truth_for_username_and_password(self):
self.assertIn('DEFAULT_USERNAME="sovran"', self.setup_service) self.assertIn('DEFAULT_USERNAME="sovran"', self.setup_service)
-3
View File
@@ -46,9 +46,7 @@ lib.mkIf config.sovran_systemsOS.features.rdp {
pkgs.gnome-remote-desktop pkgs.gnome-remote-desktop
pkgs.hostname pkgs.hostname
pkgs.openssl pkgs.openssl
pkgs.polkit
pkgs.systemd pkgs.systemd
pkgs.util-linux
]; ];
script = '' script = ''
set -euo pipefail set -euo pipefail
@@ -64,7 +62,6 @@ lib.mkIf config.sovran_systemsOS.features.rdp {
local rc=0 local rc=0
if timeout --kill-after=5s 10s \ if timeout --kill-after=5s 10s \
runuser -u gnome-remote-desktop -- \
grdctl --system "$@"; then grdctl --system "$@"; then
return 0 return 0
else else