Do you use custom policies related to the actions on files?

Continuing the discussion from Use Qubes context actions (copy-to-vm, etc.) in the Nemo file manager.

In your file manager, you have several operations on files. Have you customized them, either with Qubes OS Global config or with a policy editor?

  • I tried to restrict the copy and move operations (qubes.Filecopy) but I came up with something too strict and removed it. I just have some rules for allowing the copy from an admin qube to another qube.
  • my default disposable template is offline, so whenever I open a link in another qube:
    • only a limited set of disposable templates are allowed (offline, clearnet, vpn or whonix)
    • I’m asked to choose between them
    • I can also use an existing disposable but the sys- named disposables are tagged to be unavailable
    • for some qubes, like vault, it is allowed and the target is the vpn
  • I have something like that for opening (qubes.OpenInVM) operations
  • the file conversions have the default policies

I only have some custom policies that facilitate inter-qube file copy for cron jobs. Nothing specifically tailored for a file manager.

1 Like

I rarely use a file manager but I extensively modify operations using
custom scripts and policies.

I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.

1 Like

Only for copy - I don’t use any other actions because integrations like open, edit, and view are limiting, clunky, and cannot justify the effort to configure the receiving end properly.

All this is CLI though, I don’t use a file manager.

2 Likes