# HAPX-UI — privilege grant for the in-app (web UI) updater. # # Install as /etc/sudoers.d/hapx-ui-update, mode 0440, owner root:root, verify: # visudo -cf /etc/sudoers.d/hapx-ui-update # # The web service (unprivileged user hapx-ui) is granted exactly these: # - `hapx-ui-update preflight`: a read-only System-Check (no state change). # - starting STEP 1 (hapx-ui-update.service): download + verify only. # - starting STEP 2 (hapx-ui-activate.service): swap + restart + rollback, # run only after the operator confirms in the UI. # Both oneshots run the actual work as root in their OWN cgroup (so the binary # swap + service restart can't be killed by hapx-ui's own KillMode=control-group). # # The units' ExecStart and the helper (/usr/local/sbin/hapx-ui-update, root:root # 0755, not writable by hapx-ui) are fixed, so this is the entire attack surface. # Both systemctl paths are listed for merged-/usr layouts. hapx-ui ALL=(root) NOPASSWD: /usr/local/sbin/hapx-ui-update preflight, /usr/bin/systemctl start --no-block hapx-ui-update.service, /bin/systemctl start --no-block hapx-ui-update.service, /usr/bin/systemctl start --no-block hapx-ui-activate.service, /bin/systemctl start --no-block hapx-ui-activate.service