From 4e1bf65651344f5b72e9705af1570e88165418ff Mon Sep 17 00:00:00 2001 From: Kevin Fenzi Date: Wed, 14 Dec 2016 22:21:55 +0000 Subject: [PATCH] change koji hub perms so that autosign can move builds in secure-boot channel as needed to sign them --- roles/koji_hub/templates/hub.conf.j2 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/roles/koji_hub/templates/hub.conf.j2 b/roles/koji_hub/templates/hub.conf.j2 index d7b098fdc8..9d3bd59216 100644 --- a/roles/koji_hub/templates/hub.conf.j2 +++ b/roles/koji_hub/templates/hub.conf.j2 @@ -107,7 +107,7 @@ Plugins = fedmsg-koji-plugin runroot_hub hub_containerbuild tag = - has_perm autosign && fromtag *-signing-pending && tag *-updates-testing-pending && package kernel shim grub2 fedora-release fedora-repos pesign :: allow + has_perm autosign && fromtag *-pending && package kernel shim grub2 fedora-release fedora-repos pesign :: allow has_perm secure-boot && package kernel shim grub2 fedora-release fedora-repos pesign :: allow package kernel shim grub2 fedora-release fedora-repos pesign :: deny all :: allow