Show HN: Bor – Open-source policy management for Linux desktops
摘要
Bor v0.8.0 为 Linux 桌面策略管理新增三种策略类型:Thunderbird、Microsoft Edge for Business 和 Firewalld 区域,支持通过 agent 写入并保护托管文件。同时完成 Web UI 全面改版,引入 URL 路由、全页策略编辑器、服务端分页/过滤/排序、可访问性改进(WCAG 2.2 AA),并细化按操作划分的 RBAC 权限。安全加固包括 mTLS 身份绑定、TOTP 密钥迁移、SSRF 防护、审计日志 CSV 注入防护等,策略目录改为 protobuf 驱动,前端升级至 React 19.2 与 react-router 8.3。
荐读理由
这个开源工具在 Linux 桌面策略管理上做了扎实的工程更新,比如 mTLS 证书绑定、防篡改文件恢复、按操作细分的 RBAC,这些安全加固思路可以借鉴到你自己的服务端或代理设计里;但工具本身面向桌面端策略下发,与 AI 工程方向关联有限,迁移成本不低。
原文
Bor v0.8.0 released
Bor v0.8.0 is out. This release adds three new policy types — Thunderbird, Microsoft Edge for Business, and Firewalld zones — alongside a full web UI overhaul, finer-grained RBAC, and a dedicated security hardening pass. The complete changelog is on the GitHub release page.

Thunderbird policy type
Mozilla Thunderbird can now be managed on enrolled desktops with the same mechanism used for Firefox ESR. The agent writes the managed policies.json that Thunderbird expects, merged from all bound policies, and removing the last policy restores the original file. Flatpak installations are detected and enforced alongside RPM/DEB installations, and the managed file is protected by the tamper watcher — external edits are detected and immediately restored. The web UI ships a full policy editor with the complete Thunderbird policy catalogue.

Microsoft Edge for Business policy type
For fleets running Edge on Linux, the agent writes bor_managed.json into each Edge managed-policy directory and cleans it up from every directory when the last bound policy is removed. The web UI provides a tree-based editor with the Edge policy catalogue, JSON validation, and a setting preview before enabling.

Firewalld zone policy type
The new Firewalld policy type manages firewalld zones on enrolled nodes: services, ports, forward ports, rich rules, masquerade, interfaces, sources, and the zone target. The agent writes zone XML to /etc/firewalld/zones/, validates it with firewall-cmd --check-config, and reloads firewalld. Like all other managed files, the zone files are tamper-protected.

Polkit: variable conditions
Polkit rules now support variable conditions via action.lookup(), so a rule can match on action variables — for example allowing mounts only for removable drives. Also fixed: multiple action IDs in one rule are now correctly joined with ||.

Per-action RBAC
User and role administration is now guarded by per-action permissions instead of a single blanket permission, allowing finer-grained delegation of admin duties.
Web UI overhaul
A full modernization pass over the PatternFly 6 interface, spanning several UX sprints. The dashboard shows the new look — grouped sidebar navigation, a single left-aligned page title, and stat tiles that drill down to pre-filtered lists: click Offline and you land on the Nodes page already filtered to offline nodes.

The highlights:
URL routing — every page has a real URL with working browser back/forward and deep links; expired sessions redirect to login; a global error boundary prevents white-screen crashes.
Full-page policy editor — the policy editor is now a routed page (
/policies/:id/edit) instead of nested modals.Policy safety rails — unsaved-changes guard, confirmation for destructive type changes, JSON validation for Chrome/Edge values, a read-only Configuration view for released policies, and setting previews in the tree editors.
Scalable lists — server-side pagination, filtering, and sorting for Nodes and Compliance; search, sorting, and empty states across all list pages.
Destructive-action protection — type-to-confirm dialogs for all resource deletes, plus server-side guards that prevent deleting, disabling, or demoting the last Super Admin.
Accessibility (WCAG 2.2 AA) — accessible tree roles in the policy editors,
aria-livestatus messages, focus-ring and dark-mode/high-contrast correctness via PatternFly 6 design tokens, and an accessibility lint gate in CI.
The policy editor is now a routed, full-width page instead of stacked modals, with room for the tree-based editors behind each policy type:

Node and compliance lists are paginated, filtered, and sorted server-side, so fleets with thousands of nodes stay fast:

Plus many quality-of-life changes: policies can be released/unreleased directly from the list view, backup codes for MFA can be copied or downloaded, the login form gained a password reveal toggle and Caps Lock hint, and the sidebar is now grouped into Fleet / Policy / System.

Proto-driven policy catalogues
The Firefox, Thunderbird, Chrome, and Edge policy catalogues shown in the web UI are now generated from protobuf annotations — one source of truth shared by the server, agent, and frontend.
Security hardening
This release includes a dedicated hardening pass:
Agent identity is now strictly bound to the mTLS client certificate, and MFA/RBAC enforcement paths were hardened on the server.
Legacy SHA-256-encrypted TOTP secrets are transparently migrated to HKDF-derived encryption on first read.
The Ubuntu PPA and Fedora COPR repository import helpers now block redirect-based SSRF; only allowlisted redirect targets are followed.
Audit log CSV export is guarded against spreadsheet formula injection.
The auto-generated initial admin password is no longer printed to the server log (where it would land in journald or centralized logging); it is written to a root-only file instead.
The server TLS certificate is automatically regenerated when its SANs no longer match the configured hostnames.
All open Dependabot alerts were resolved, including the react-router RSC CSRF advisory (GHSA-qwww-vcr4-c8h2).

Platform updates
The frontend moved to React 19.2 and react-router 8.3, with TypeScript typecheck now enforced in CI. Server and agent dependencies were bumped, including gRPC 1.82.1 and golang.org/x/crypto 0.52.0.
Upgrade notes
Agents must be upgraded to v0.8.0 to enforce the new Thunderbird, Edge, and Firewalld policy types; older agents ignore policy types they do not understand.
The protobuf policy schema gained
thunderbird.protoandfirewalld.protoand extends the polkit and edge messages — regenerate any external tooling built againstproto/policy/.Frontend development now requires Node.js 22.22+.
Download
Packages for Debian/Ubuntu, RHEL/Fedora/SUSE, Alpine Linux, and Arch Linux across x86_64, aarch64, and ppc64le are available on the Download page.
这条对你有帮助吗?