feat(profile): restrict dbus in dbus

even dbus-* profiles do not need access to the full bus.
This commit is contained in:
Alexandre Pujol 2024-09-25 00:48:42 +01:00
parent 69f9e8464f
commit 156cce5362
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
4 changed files with 4 additions and 5 deletions

View file

@ -25,8 +25,7 @@ profile dbus-accessibility @{exec_path} flags=(attach_disconnected) {
signal (receive) set=(term hup kill) peer=dbus-session,
signal (receive) set=(term hup kill) peer=gdm{,-session-worker},
dbus bus=accessibility,
#aa:dbus own bus=accessibility name=org.freedesktop.DBus
#aa:dbus own bus=session name=org.a11y.{B,b}us
dbus receive bus=session

View file

@ -29,7 +29,7 @@ profile dbus-session flags=(attach_disconnected) {
signal (send) set=(term hup kill) peer=dconf-service,
signal (send) set=(term hup kill) peer=xdg-*,
dbus bus=session,
#aa:dbus own bus=session name=org.freedesktop.DBus
@{exec_path} mrix,

View file

@ -32,7 +32,7 @@ profile dbus-system flags=(attach_disconnected) {
ptrace (read) peer=@{p_systemd},
dbus bus=system,
#aa:dbus own bus=system name=org.freedesktop.DBus
@{exec_path} mrix,