refactor(profiles): move thunderbird and code profiles.

This commit is contained in:
Alexandre Pujol 2023-07-20 20:54:36 +01:00
parent ce7209f2a1
commit 2a4fa1e6de
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
2 changed files with 0 additions and 0 deletions

View file

@ -1,69 +0,0 @@
# apparmor.d - Full set of apparmor profiles
# Copyright (C) 2019-2021 Mikhail Morfikov
# Copyright (C) 2023 Alexandre Pujol <alexandre@pujol.io>
# SPDX-License-Identifier: GPL-2.0-only
abi <abi/3.0>,
include <tunables/global>
@{exec_path} = @{bin}/code /usr/share/code/{bin/,}code
profile code @{exec_path} {
include <abstractions/base>
include <abstractions/chromium-common>
include <abstractions/dconf-write>
include <abstractions/fontconfig-cache-read>
include <abstractions/fonts>
include <abstractions/freedesktop.org>
include <abstractions/gtk>
include <abstractions/nameservice-strict>
include <abstractions/opencl>
include <abstractions/ssl_certs>
# ptrace (read) peer=lsb_release,
@{exec_path} mrix,
@{lib}/code/extensions/git/dist/askpass.sh rPx,
@{lib}/code/extensions/git/dist/git-editor.sh rPx,
# The shell is not confined on purpose.
@{bin}/{,b,d,rb}ash rUx,
@{bin}/{c,k,tc,z}sh rUx,
@{bin}/git rPx,
@{bin}/gpg{,2} rPUx,
@{bin}/lsb_release rPx -> lsb_release,
# /usr/share/code/** r,
# /usr/share/code/libffmpeg.so mr,
# /usr/share/code/resources/**/bin/* rix,
# /usr/share/code/resources/**.node mr,
/var/lib/dbus/machine-id r,
/etc/machine-id r,
owner @{user_config_dirs}/Code/ rw,
owner @{user_config_dirs}/Code/** rwkl -> {HOME}/.config/Code/**,
owner @{HOME}/.vscode/ rw,
owner @{HOME}/.vscode/** rwlk -> @{HOME}/.vscode/**,
owner @{user_projects_dirs}/ r,
owner @{user_projects_dirs}/** rwkl -> @{user_projects_dirs}/**,
owner /tmp/@{uuid} rw,
owner /tmp/vscode-*/{,**} rw,
owner /tmp/vscode-ipc-@{uuid}.sock rw,
owner @{run}/user/@{uid}/vscode-@{hex}-*-{shared,main}.sock rw,
owner @{run}/user/@{uid}/vscode-git-askpass-@{hex}.sock rw,
@{PROC}/ r,
@{PROC}/@{pid}/fd/ r,
owner @{PROC}/@{pids}/task/ r,
owner @{PROC}/@{pids}/task/@{tid}/status r,
owner @{PROC}/@{pid}/mountinfo r,
owner @{PROC}/@{pid}/mounts r,
include if exists <local/code>
}

View file

@ -1,329 +0,0 @@
# apparmor.d - Full set of apparmor profiles
# Copyright (C) 2015-2021 Mikhail Morfikov
# SPDX-License-Identifier: GPL-2.0-only
# Useful info:
# http://kb.mozillazine.org/Files_and_folders_in_the_profile_-_Thunderbird
abi <abi/3.0>,
include <tunables/global>
@{FIREFOX_BIN} = @{lib}/firefox{,-esr}/firefox
@{FIREFOX_BIN} += /opt/firefox{,-esr}/firefox
@{MOZ_LIBDIR} = @{lib}/thunderbird
@{MOZ_HOMEDIR} = @{HOME}/.thunderbird
@{MOZ_CACHEDIR} = @{user_cache_dirs}/thunderbird
@{exec_path} = @{MOZ_LIBDIR}/thunderbird{,-bin}
@{exec_path} += @{bin}/thunderbird
profile thunderbird @{exec_path} {
include <abstractions/base>
include <abstractions/consoles>
include <abstractions/nameservice-strict>
include <abstractions/gtk>
include <abstractions/wayland>
include <abstractions/mesa>
include <abstractions/opencl-intel>
include <abstractions/nvidia>
include <abstractions/vulkan>
include <abstractions/fonts>
include <abstractions/fontconfig-cache-read>
include <abstractions/freedesktop.org>
include <abstractions/audio>
include <abstractions/enchant>
include <abstractions/user-download-strict>
include <abstractions/thumbnails-cache-read>
include <abstractions/openssl>
include <abstractions/ibus>
include <abstractions/dconf-write>
include <abstractions/dbus-strict>
include <abstractions/dbus-session-strict>
include <abstractions/dbus-gtk>
ptrace peer=@{profile_name},
unix (send, receive) type=stream peer=(addr=none, label=xorg),
network inet dgram,
network inet6 dgram,
network inet stream,
network inet6 stream,
network netlink raw,
# The following rules are needed only when the kernel.unprivileged_userns_clone option is set
# to "1".
capability sys_admin,
capability sys_chroot,
owner @{PROC}/@{pid}/setgroups w,
owner @{PROC}/@{pid}/gid_map w,
owner @{PROC}/@{pid}/uid_map w,
dbus send bus=session path=/org/freedesktop/DBus
interface=org.freedesktop.DBus
member=RequestName
peer=(name=org.freedesktop.DBus),
dbus send bus=system path=/org/freedesktop/RealtimeKit[0-9]*
member={Get,MakeThreadHighPriority,MakeThreadRealtime}
peer=(name=org.freedesktop.RealtimeKit[0-9]*),
dbus send bus=system path=/org/freedesktop/UPower
interface=org.freedesktop.UPower
member=EnumerateDevices
peer=(name=org.freedesktop.UPower),
dbus send bus=session path=/ca/desrt/dconf/Writer/user
interface=ca.desrt.dconf.Writer
member={Change,Notify}
peer=(name=ca.desrt.dconf),
dbus send bus=session path=/org/freedesktop/portal/desktop
interface=org.freedesktop.DBus.Properties
member=GetAll
peer=(name=:*),
dbus send bus=session path=/org/freedesktop/portal/desktops
interface=org.freedesktop.portal.Settings
member=Read
peer=(name=:*),
dbus receive bus=system path=/org/freedesktop/login[0-9]*
interface=org.freedesktop.login[0-9]*.Manager
member={UserAdded,UserRemoved}
peer=(name=:*, label=systemd-logind),
dbus bind bus=session
name=org.mozilla.thunderbird.*,
deny dbus send bus=system path=/org/freedesktop/hostname[0-9]*,
owner /tmp/dbus-[0-9a-zA-Z]* rw,
@{exec_path} mrix,
@{MOZ_LIBDIR}/thunderbird-wrapper-helper.sh rix,
@{bin}/{,ba,da}sh rix,
@{bin}/sed rix,
@{bin}/date rix,
@{bin}/tr rix,
@{bin}/which{,.debianutils} rix,
@{bin}/ps rPx,
@{bin}/dig rix,
# Thunderbird files
/usr/share/thunderbird/{,**} r,
/etc/thunderbird/{,**} r,
# Extensions
@{MOZ_LIBDIR}/extensions/{,**} r,
/usr/share/mozilla/extensions/{,**} r,
/usr/share/lightning/{,**} r,
# Thunderbird home files
owner @{MOZ_HOMEDIR}/ rw,
owner "@{MOZ_HOMEDIR}/{Crash Reports,Pending Pings}/" rw,
owner "@{MOZ_HOMEDIR}/Crash Reports/**" rw,
owner @{MOZ_HOMEDIR}/*.*/ rw,
owner @{MOZ_HOMEDIR}/*.*/** rwk,
deny @{MOZ_HOMEDIR}/*.*/pepmda/ rw,
deny @{MOZ_HOMEDIR}/*.*/pepmda/** rwklmx,
owner @{MOZ_HOMEDIR}/profiles.ini rw,
owner @{MOZ_HOMEDIR}/installs.ini rw,
deny @{HOME}/.mozilla/** mrwkl,
# Cache
owner @{user_cache_dirs}/ rw,
owner @{MOZ_CACHEDIR}/{,**} rw,
# Needed for system mails
owner /var/mail/* rwk,
owner @{HOME}/ r,
owner @{HOME}/Mail/ rw,
owner @{HOME}/Mail/** rwl -> @{HOME}/Mail/**,
owner @{user_share_dirs}/ r,
# Spellcheck
@{bin}/locale rix,
# System integration
/etc/mime.types r,
owner @{user_config_dirs}/mimeapps.list.* rw,
# KDE system keyring
@{lib}/@{multiarch}/qt5/plugins/kf5/org.kde.kwindowsystem.platforms/KF5WindowSystemX11Plugin.so mr,
/usr/share/xul-ext/kwallet5/* r,
/etc/xul-ext/kwallet5.js r,
owner @{user_config_dirs}/kwalletrc r,
# QT5
owner @{user_config_dirs}/qt5ct/{,**} r,
/usr/share/qt5ct/** r,
# gnome-tiny
/usr/share/gvfs/remote-volume-monitors/{,*} r,
@{run}/mount/utab r,
deny @{sys}/devices/system/cpu/present r,
deny @{sys}/devices/system/cpu/cpufreq/policy[0-9]/cpuinfo_max_freq r,
deny @{sys}/devices/system/cpu/cpu[0-9]/cache/index[0-9]/size r,
owner @{PROC}/@{pid}/fd/ r,
owner @{PROC}/@{pid}/cgroup r,
owner @{PROC}/@{pid}/stat r,
owner @{PROC}/@{pid}/statm r,
owner @{PROC}/@{pid}/smaps r,
owner @{PROC}/@{pid}/comm r,
deny owner @{PROC}/@{pid}/cmdline r,
deny owner @{PROC}/@{pid}/environ r,
owner @{PROC}/@{pid}/task/ r,
owner @{PROC}/@{pid}/task/@{tid}/stat r,
# To remove the following error:
# GLib-GIO-WARNING **: Error creating IO channel for /proc/self/mountinfo: Permission denied
# (g-file-error-quark, 2)
owner @{PROC}/@{pid}/mountinfo r,
owner @{PROC}/@{pid}/mounts r,
deny @{PROC}/@{pids}/net/arp r,
deny @{PROC}/@{pids}/net/route r,
# for dig
owner @{PROC}/@{pid}/task/@{tid}/comm rw,
# TMP files
/var/tmp/ r,
/tmp/ r,
owner /tmp/* rw,
owner /tmp/thunderbird{,_*}/ rw,
owner /tmp/thunderbird{,_*}/* rwk,
owner /tmp/mozilla_*/ rw,
owner /tmp/mozilla_*/* rw,
owner /tmp/MozillaMailnews/ rw,
owner /tmp/MozillaMailnews/*.msf rw,
owner /tmp/Temp-@{uuid}/ rw,
deny /dev/ r,
/dev/urandom w,
/dev/shm/ r,
owner /dev/shm/org.chromium.* rw,
owner /dev/shm/org.mozilla.ipc.@{pid}.[0-9]* rw,
owner /dev/shm/wayland.mozilla.ipc.[0-9]* rw,
/etc/fstab r,
/etc/mailcap r,
/etc/timezone r,
/usr/share/sounds/freedesktop/stereo/*.oga r,
# Silencer
deny @{lib}/thunderbird/** w,
@{bin}/lsb_release rPx -> lsb_release,
@{bin}/xdg-{open,mime} rCx -> open,
@{bin}/exo-open rCx -> open,
@{lib}/@{multiarch}/glib-[0-9]*/gio-launch-desktop rCx -> open,
# Needed for enigmail
/usr/share/xul-ext/enigmail/{,**} r,
@{bin}/gpgconf rCx -> gpg,
@{bin}/gpg-connect-agent rCx -> gpg,
@{bin}/gpg{,2} rCx -> gpg,
@{bin}/gpgsm rCx -> gpg,
# Allowed apps to open
@{bin}/qpdfview rPx,
@{bin}/viewnior rPUx,
@{bin}/engrampa rPx,
@{bin}/geany rPx,
@{FIREFOX_BIN} rPx,
# file_inherit
owner /dev/tty[0-9]* rw,
owner @{HOME}/.xsession-errors w,
@{sys}/cgroup/cpu,cpuacct/user.slice/cpu.cfs_quota_us r,
@{sys}/fs/cgroup/cpu,cpuacct/cpu.cfs_quota_us r,
profile gpg {
include <abstractions/base>
include <abstractions/consoles>
network inet stream,
network inet6 stream,
network netlink raw,
@{bin}/gpgconf mr,
@{bin}/gpg{,2} mr,
@{bin}/gpg-connect-agent mr,
@{bin}/gpgsm mr,
@{bin}/gpg-agent rix,
owner @{HOME}/@{XDG_GPG_DIR}/ rw,
owner @{HOME}/@{XDG_GPG_DIR}/** rwkl -> @{HOME}/@{XDG_GPG_DIR}/**,
owner /tmp/nscopy.tmp w,
# For encryption + signature
owner /tmp/gpgOutput.* rw,
# for inline pgp
owner /tmp/encfile rw,
owner /tmp/encfile-[0-9]* rw,
# for signature generation
owner /tmp/nsemail.eml w,
owner /tmp/nsemail-[0-9]*.eml w,
# for signature verifications
owner /tmp/data.sig r,
owner /tmp/data-[0-9]*.sig r,
@{PROC}/@{pids}/fd/ r,
# file_inherit
owner /dev/tty[0-9]* rw,
deny owner @{MOZ_HOMEDIR}/*.*/** rw,
deny owner @{MOZ_CACHEDIR}/** rw,
deny /usr/share/thunderbird/** r,
deny /usr/share/sounds/freedesktop/stereo/*.oga r,
deny owner /tmp/thunderbird{,_*}/* rwk,
deny /dev/shm/org.chromium.* r,
deny owner /dev/shm/org.mozilla.ipc.[0-9]*.[0-9]* rw,
owner /tmp/ns* rw,
include if exists <local/thunderbird_gpg>
}
profile open {
include <abstractions/base>
include <abstractions/xdg-open>
@{bin}/xdg-open mr,
@{bin}/exo-open mr,
@{lib}/@{multiarch}/glib-[0-9]*/gio-launch-desktop mr,
@{bin}/{,ba,da}sh rix,
@{bin}/{,m,g}awk rix,
@{bin}/readlink rix,
@{bin}/basename rix,
@{bin}/xfce4-mime-helper rix,
owner @{HOME}/ r,
owner @{run}/user/@{uid}/ r,
# Allowed apps to open
@{bin}/qpdfview rPx,
@{bin}/viewnior rPUx,
@{bin}/engrampa rPx,
@{bin}/geany rPx,
@{FIREFOX_BIN} rPx,
# file_inherit
owner @{HOME}/.xsession-errors w,
include if exists <local/thunderbird_open>
}
include if exists <local/thunderbird>
}