feat(profile): enable desktop user variable everywhere.
Also restrict access to these files.
This commit is contained in:
parent
a370281e9b
commit
3787eb1745
26 changed files with 80 additions and 119 deletions
|
|
@ -58,9 +58,9 @@ profile snap @{exec_path} {
|
|||
/var/cache/snapd/commands.db rwk,
|
||||
/var/cache/snapd/names r,
|
||||
|
||||
@{DESKTOP_HOME}/snap/{,**} rw,
|
||||
@{HOME}/snap/{,**} rw,
|
||||
/snap/{,**} rw,
|
||||
/var/lib/gdm{,3}/snap/{,**} rw,
|
||||
|
||||
owner /tmp/snapd-auto-import-mount-@{int}/ rw,
|
||||
|
||||
|
|
|
|||
|
|
@ -36,11 +36,9 @@ profile spice-vdagent @{exec_path} flags=(attach_disconnected) {
|
|||
|
||||
@{exec_path} mr,
|
||||
|
||||
/var/lib/gdm{3,}/.config/pulse/cookie rk,
|
||||
/var/lib/gdm{3,}/.config/user-dirs.dirs r,
|
||||
|
||||
/var/lib/nscd/passwd r,
|
||||
|
||||
owner @{desktop_config_dirs}/user-dirs.dirs r,
|
||||
owner @{user_config_dirs}/user-dirs.dirs r,
|
||||
|
||||
@{run}/spice-vdagentd/spice-vdagent-sock rw,
|
||||
|
|
|
|||
|
|
@ -41,9 +41,9 @@ profile wireplumber @{exec_path} {
|
|||
|
||||
/etc/machine-id r,
|
||||
|
||||
/var/lib/gdm{3,}/.local/state/ w,
|
||||
/var/lib/gdm{3,}/.local/ w,
|
||||
/var/lib/gdm{3,}/.local/state/wireplumber/{,**} rw,
|
||||
owner @{desktop_local_dirs}/ w,
|
||||
owner @{desktop_local_dirs}/state/ w,
|
||||
owner @{desktop_local_dirs}/state/wireplumber/{,**} rw,
|
||||
|
||||
owner @{HOME}/.local/ w,
|
||||
owner @{user_state_dirs}/ w,
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue