is there a way to limit
qvm-run-vm inside a qube to specific service /
.desktop file, similar to
qvm-run --service qubes.StartApp+my-service in
This at least would allow qube B to control the commands invoked from qube A, providing security benefits.
Background: I am evaluating different alternatives to have disposables in combination with minimal persistent state (in form of separate data qubes).