# HAPX-UI network helper: the service user may run ONLY the specific verbs the # web UI actually needs, as root. The verbs are pinned here (defence in depth on # top of the helper's own argument validation), and — crucially — `iface-rollback` # is deliberately NOT granted: it is invoked only by the root-owned rollback timer, # never by the service user. `*` matches the already-validated arguments. Cmnd_Alias HAPX_NETCFG = \ /usr/local/sbin/hapx-ui-netcfg status, \ /usr/local/sbin/hapx-ui-netcfg iface-pending, \ /usr/local/sbin/hapx-ui-netcfg ipv6 on, \ /usr/local/sbin/hapx-ui-netcfg ipv6 off, \ /usr/local/sbin/hapx-ui-netcfg flushdns, \ /usr/local/sbin/hapx-ui-netcfg dns *, \ /usr/local/sbin/hapx-ui-netcfg iface-apply *, \ /usr/local/sbin/hapx-ui-netcfg iface-confirm *, \ /usr/local/sbin/hapx-ui-netcfg timezone * hapx-ui ALL=(root) NOPASSWD: HAPX_NETCFG