diff --git a/apparmor.d/abstractions/evince b/apparmor.d/abstractions/evince index efcfb03f2..bcfd6886c 100644 --- a/apparmor.d/abstractions/evince +++ b/apparmor.d/abstractions/evince @@ -120,5 +120,4 @@ include #owner @{HOME}/.mozilla/**/*Cache/* r, - # Site-specific additions and overrides. See local/README for details. - include + include if exists diff --git a/apparmor.d/abstractions/libvirt-lxc b/apparmor.d/abstractions/libvirt-lxc index 72278b5bc..0ea35ad78 100644 --- a/apparmor.d/abstractions/libvirt-lxc +++ b/apparmor.d/abstractions/libvirt-lxc @@ -117,5 +117,4 @@ deny /sys/fs/cgroup?*{,/**} wklx, deny /sys/fs?*{,/**} wklx, - # Site-specific additions and overrides. See local/README for details. - #include + include if exists diff --git a/apparmor.d/abstractions/libvirt-qemu b/apparmor.d/abstractions/libvirt-qemu index 677a46403..168f6e187 100644 --- a/apparmor.d/abstractions/libvirt-qemu +++ b/apparmor.d/abstractions/libvirt-qemu @@ -244,5 +244,4 @@ / r, # harmless on any lsb compliant system /sys/bus/nd/devices/{,**/} r, - # Site-specific additions and overrides. See local/README for details. - #include + include if exists diff --git a/apparmor.d/groups/apt/usr.sbin.apt-cacher-ng b/apparmor.d/groups/apt/usr.sbin.apt-cacher-ng index 63b116963..f9f8b8d8e 100644 --- a/apparmor.d/groups/apt/usr.sbin.apt-cacher-ng +++ b/apparmor.d/groups/apt/usr.sbin.apt-cacher-ng @@ -4,13 +4,13 @@ @{APT_CACHER_NG_CACHE_DIR}=/var/cache/apt-cacher-ng -#include +include -profile apt-cacher-ng /usr/sbin/apt-cacher-ng { - #include - #include - #include - #include +profile apt-cacher-ng /usr/sbin/apt-cacher-ng flags=(complain) { + include + include + include + include /etc/apt-cacher-ng/ r, /etc/apt-cacher-ng/** r, @@ -35,6 +35,5 @@ profile apt-cacher-ng /usr/sbin/apt-cacher-ng { # used by libevent @{PROC}/sys/kernel/random/uuid r, - # Site-specific additions and overrides. See local/README for details. - #include + include if exists } diff --git a/apparmor.d/groups/browsers/torbrowser.Browser.firefox b/apparmor.d/groups/browsers/torbrowser.Browser.firefox index 284869de3..05953ab17 100644 --- a/apparmor.d/groups/browsers/torbrowser.Browser.firefox +++ b/apparmor.d/groups/browsers/torbrowser.Browser.firefox @@ -148,5 +148,5 @@ profile torbrowser_firefox @{torbrowser_firefox_executable} { # Yubikey NEO also needs this: /sys/devices/**/hidraw/hidraw*/uevent r, - include + include if exists } diff --git a/apparmor.d/groups/browsers/torbrowser.Browser.plugin-container b/apparmor.d/groups/browsers/torbrowser.Browser.plugin-container index b96dcb511..a94d01305 100644 --- a/apparmor.d/groups/browsers/torbrowser.Browser.plugin-container +++ b/apparmor.d/groups/browsers/torbrowser.Browser.plugin-container @@ -100,5 +100,5 @@ profile torbrowser_plugin_container { deny /etc/pulse/client.conf r, deny /usr/bin/pulseaudio x, - include + include if exists } diff --git a/apparmor.d/groups/browsers/torbrowser.Tor.tor b/apparmor.d/groups/browsers/torbrowser.Tor.tor index cb15d6c8f..cef2f6016 100644 --- a/apparmor.d/groups/browsers/torbrowser.Tor.tor +++ b/apparmor.d/groups/browsers/torbrowser.Tor.tor @@ -42,5 +42,5 @@ profile torbrowser_tor @{torbrowser_tor_executable} { # OnionShare compatibility /tmp/onionshare/** rw, - include + include if exists } diff --git a/apparmor.d/profiles-a-l/child-lsb_release b/apparmor.d/profiles-a-l/child-lsb_release index ecb619961..9db6050a5 100644 --- a/apparmor.d/profiles-a-l/child-lsb_release +++ b/apparmor.d/profiles-a-l/child-lsb_release @@ -58,6 +58,5 @@ profile child-lsb_release { # deny /tmp/gtalkplugin.log w, /dev/dri/card[0-9]* rw, - # Site-specific additions and overrides. See local/README for details. include if exists } diff --git a/apparmor.d/profiles-m-z/system_tor b/apparmor.d/profiles-m-z/system_tor index 5e927f2ff..dfea51dec 100644 --- a/apparmor.d/profiles-m-z/system_tor +++ b/apparmor.d/profiles-m-z/system_tor @@ -21,6 +21,5 @@ profile system_tor flags=(attach_disconnected) { /{,var/}run/tor/control.authcookie.tmp rw, /{,var/}run/systemd/notify w, - # Site-specific additions and overrides. See local/README for details. - include + include if exists } diff --git a/apparmor.d/profiles-m-z/usr.bin.irssi b/apparmor.d/profiles-m-z/usr.bin.irssi index 149c2e5ff..acdf9eab8 100644 --- a/apparmor.d/profiles-m-z/usr.bin.irssi +++ b/apparmor.d/profiles-m-z/usr.bin.irssi @@ -49,6 +49,5 @@ include # for fnotify owner @{HOME}/.irssi/fnotify rwk, - # Site-specific additions and overrides. See local/README for details. - include + include if exists } diff --git a/apparmor.d/profiles-m-z/usr.bin.man b/apparmor.d/profiles-m-z/usr.bin.man index 4b87c63b7..0eb54fdbc 100644 --- a/apparmor.d/profiles-m-z/usr.bin.man +++ b/apparmor.d/profiles-m-z/usr.bin.man @@ -49,8 +49,7 @@ include signal peer=/usr/bin/man//&man_groff, signal peer=/usr/bin/man//&man_filter, - # Site-specific additions and overrides. See local/README for details. - include + include if exists } profile man_groff { diff --git a/apparmor.d/profiles-m-z/usr.bin.pidgin b/apparmor.d/profiles-m-z/usr.bin.pidgin index dab7ac957..716b15609 100644 --- a/apparmor.d/profiles-m-z/usr.bin.pidgin +++ b/apparmor.d/profiles-m-z/usr.bin.pidgin @@ -82,6 +82,5 @@ include owner @{PROC}/@{pid}/auxv r, owner @{PROC}/@{pid}/fd/ r, - # Site-specific additions and overrides. See local/README for details. - include + include if exists } diff --git a/apparmor.d/profiles-m-z/usr.bin.tcpdump b/apparmor.d/profiles-m-z/usr.bin.tcpdump index ae69e145a..3d0fef2cf 100644 --- a/apparmor.d/profiles-m-z/usr.bin.tcpdump +++ b/apparmor.d/profiles-m-z/usr.bin.tcpdump @@ -60,6 +60,5 @@ profile tcpdump /usr/sbin/tcpdump { /usr/sbin/tcpdump mr, - # Site-specific additions and overrides. See local/README for details. - include + include if exists } diff --git a/apparmor.d/profiles-m-z/usr.bin.totem b/apparmor.d/profiles-m-z/usr.bin.totem index df3877b34..2adec6a6d 100644 --- a/apparmor.d/profiles-m-z/usr.bin.totem +++ b/apparmor.d/profiles-m-z/usr.bin.totem @@ -54,6 +54,5 @@ /sys/devices/pci[0-9]*/**/config r, /sys/devices/pci[0-9]*/**/{,subsystem_}{device,vendor} r, - # Site-specific additions and overrides. See local/README for details. - #include + include if exists } diff --git a/apparmor.d/profiles-m-z/usr.bin.totem-previewers b/apparmor.d/profiles-m-z/usr.bin.totem-previewers index 822c1691c..2b23de553 100644 --- a/apparmor.d/profiles-m-z/usr.bin.totem-previewers +++ b/apparmor.d/profiles-m-z/usr.bin.totem-previewers @@ -23,8 +23,7 @@ include /usr/bin/totem-video-thumbnailer rm, - # Site-specific additions and overrides. See local/README for details. - include + include if exists } /usr/bin/totem-audio-preview flags=(attach_disconnected) { @@ -37,6 +36,5 @@ include owner @{HOME}/[^.]* rw, owner @{HOME}/[^.]*/** rw, - # Site-specific additions and overrides. See local/README for details. - include + include if exists } diff --git a/apparmor.d/profiles-m-z/usr.lib.libvirt.virt-aa-helper b/apparmor.d/profiles-m-z/usr.lib.libvirt.virt-aa-helper index 894c3e7cb..144fc277b 100644 --- a/apparmor.d/profiles-m-z/usr.lib.libvirt.virt-aa-helper +++ b/apparmor.d/profiles-m-z/usr.lib.libvirt.virt-aa-helper @@ -69,6 +69,5 @@ profile virt-aa-helper /usr/lib/libvirt/virt-aa-helper { /**.[iI][sS][oO] r, /**/disk{,.*} r, - # Site-specific additions and overrides. See local/README for details. - include + include if exists } diff --git a/apparmor.d/profiles-m-z/usr.sbin.cupsd b/apparmor.d/profiles-m-z/usr.sbin.cupsd index 2f88a04dc..c49c3c60a 100644 --- a/apparmor.d/profiles-m-z/usr.sbin.cupsd +++ b/apparmor.d/profiles-m-z/usr.sbin.cupsd @@ -173,8 +173,7 @@ unix, } - # Site-specific additions and overrides. See local/README for details. - #include + include if exists } # separate profile since this needs to write into /home diff --git a/apparmor.d/profiles-m-z/usr.sbin.libvirtd b/apparmor.d/profiles-m-z/usr.sbin.libvirtd index 9ea5bfede..4188db7e5 100644 --- a/apparmor.d/profiles-m-z/usr.sbin.libvirtd +++ b/apparmor.d/profiles-m-z/usr.sbin.libvirtd @@ -136,6 +136,5 @@ profile libvirtd /usr/sbin/libvirtd flags=(attach_disconnected) { /usr/{lib,lib64,lib/qemu,libexec}/qemu-bridge-helper rmix, } - # Site-specific additions and overrides. See local/README for details. - #include + include if exists }