feat(profiles): replace old [0-9]* glob by @{int}

Beware some [0-9]* glob are actually not proper @{int}.
This commit is contained in:
Alexandre Pujol 2023-08-18 17:09:53 +01:00
parent 8ea4491a56
commit 275d6b6e62
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
368 changed files with 637 additions and 636 deletions

View file

@ -157,8 +157,8 @@ profile pacman @{exec_path} {
@{run}/utmp rk,
/dev/tty[0-9]* rw,
owner /dev/pts/[0-9]* rw,
/dev/tty@{int} rw,
owner /dev/pts/@{int} rw,
# Silencer,
deny /tmp/ r,
@ -184,8 +184,8 @@ profile pacman @{exec_path} {
deny @{user_share_dirs}/sddm/* rw,
/dev/tty[0-9]* rw,
owner /dev/pts/[0-9]* rw,
/dev/tty@{int} rw,
owner /dev/pts/@{int} rw,
deny network inet stream,
deny network inet6 stream,

View file

@ -17,7 +17,7 @@ profile pacman-conf @{exec_path} flags=(attach_disconnected) {
/etc/pacman.d/mirrorlist r,
/etc/pacman.d/*-mirrorlist r,
/dev/tty[0-9]* rw,
/dev/tty@{int} rw,
# Inherit Silencer
deny network inet6 stream,

View file

@ -24,8 +24,8 @@ profile pacman-hook-depmod @{exec_path} {
/usr/lib/modules/*/{,**} rw,
/dev/tty rw,
/dev/tty[0-9]* rw,
owner /dev/pts/[0-9]* rw,
/dev/tty@{int} rw,
owner /dev/pts/@{int} rw,
# Inherit Silencer
deny network inet6 stream,

View file

@ -24,8 +24,8 @@ profile pacman-hook-gtk @{exec_path} {
/usr/share/icons/{,**} rw,
/dev/tty rw,
/dev/tty[0-9]* rw,
owner /dev/pts/[0-9]* rw,
/dev/tty@{int} rw,
owner /dev/pts/@{int} rw,
# Inherit Silencer
deny network inet6 stream,

View file

@ -24,8 +24,8 @@ profile pacman-hook-perl @{exec_path} {
@{lib}/perl[0-9]*/{,**} r,
/dev/tty rw,
/dev/tty[0-9]* rw,
owner /dev/pts/[0-9]* rw,
/dev/tty@{int} rw,
owner /dev/pts/@{int} rw,
# Inherit silencer
deny network inet6 stream,

View file

@ -31,8 +31,8 @@ profile pacman-hook-systemd @{exec_path} {
/usr/ rw,
/dev/tty rw,
/dev/tty[0-9]* rw,
owner /dev/pts/[0-9]* rw,
/dev/tty@{int} rw,
owner /dev/pts/@{int} rw,
# Inherit silencer
deny network inet6 stream,

View file

@ -37,8 +37,8 @@ profile reflector @{exec_path} flags=(attach_disconnected) {
@{PROC}/cmdline r,
@{PROC}/sys/kernel/osrelease r,
/dev/tty[0-9]* rw,
owner /dev/pts/[0-9]* rw,
/dev/tty@{int} rw,
owner /dev/pts/@{int} rw,
include if exists <local/reflector>
}