chore: enforce indentation consistency across profile.
This commit is contained in:
parent
6e2d817805
commit
37bafddc80
30 changed files with 181 additions and 182 deletions
|
|
@ -15,7 +15,7 @@ profile avahi-browse @{exec_path} {
|
|||
include <abstractions/consoles>
|
||||
|
||||
dbus receive bus=system path=/Client@{int}/ServiceTypeBrowser@{int}
|
||||
interface=org.freedesktop.Avahi.ServiceTypeBrowser
|
||||
interface=org.freedesktop.Avahi.ServiceTypeBrowser
|
||||
member={ItemNew,AllForNow,CacheExhausted}
|
||||
peer=(name=:*, label=avahi-daemon),
|
||||
|
||||
|
|
|
|||
|
|
@ -26,7 +26,7 @@ profile msedge @{exec_path} {
|
|||
|
||||
@{lib_dirs}/xdg-mime rix, #-> xdg-mime,
|
||||
@{lib_dirs}/xdg-settings rix, #-> xdg-settings,
|
||||
|
||||
|
||||
@{lib_dirs}/microsoft-edge{,beta,-dev} rPx,
|
||||
@{lib_dirs}/chrome_crashpad_handler rPx -> msedge//&msedge-crashpad-handler,
|
||||
|
||||
|
|
|
|||
|
|
@ -16,10 +16,10 @@ profile ibus-memconf @{exec_path} flags=(attach_disconnected) {
|
|||
|
||||
signal (receive) set=(term) peer=ibus-daemon,
|
||||
|
||||
dbus receive bus=session
|
||||
interface=org.freedesktop.DBus.Introspectable
|
||||
member=Introspect
|
||||
peer=(name=:*, label=gnome-shell),
|
||||
dbus receive bus=session
|
||||
interface=org.freedesktop.DBus.Introspectable
|
||||
member=Introspect
|
||||
peer=(name=:*, label=gnome-shell),
|
||||
|
||||
@{exec_path} mr,
|
||||
|
||||
|
|
|
|||
|
|
@ -74,7 +74,7 @@ profile cron @{exec_path} flags=(attach_disconnected) {
|
|||
|
||||
owner @{tmp}/#@{int} rw,
|
||||
|
||||
include if exists <local/cron_run-parts>
|
||||
include if exists <local/cron_run-parts>
|
||||
}
|
||||
|
||||
include if exists <local/cron>
|
||||
|
|
|
|||
|
|
@ -128,7 +128,7 @@ profile gnome-software @{exec_path} {
|
|||
owner @{PROC}/@{pid}/task/@{tid}/comm rw,
|
||||
|
||||
/dev/fuse rw,
|
||||
|
||||
|
||||
deny owner @{user_share_dirs}/gvfs-metadata/* r,
|
||||
|
||||
profile gpg {
|
||||
|
|
|
|||
|
|
@ -39,7 +39,7 @@ profile hyprland @{exec_path} flags=(attach_disconnected) {
|
|||
owner /dev/shm/.org.chromium.Chromium.@{rand6} rw,
|
||||
|
||||
@{run}/systemd/sessions/@{int} r,
|
||||
|
||||
|
||||
@{run}/udev/data/+acpi:* r, # for acpi
|
||||
@{run}/udev/data/+dmi:id r, # for motherboard info
|
||||
@{run}/udev/data/+drm:card@{int}-* r, # For screen outputs
|
||||
|
|
|
|||
|
|
@ -22,7 +22,7 @@ profile iwd @{exec_path} {
|
|||
network netlink dgram,
|
||||
network alg seqpacket,
|
||||
|
||||
@{exec_path} mr,
|
||||
@{exec_path} mr,
|
||||
|
||||
/etc/iwd/{,**} r,
|
||||
/var/lib/iwd/{,**} rw,
|
||||
|
|
|
|||
|
|
@ -48,9 +48,9 @@ profile mullvad-daemon @{exec_path} flags=(attach_disconnected) {
|
|||
owner /var/cache/mullvad-vpn/{,*} rw,
|
||||
owner /var/log/mullvad-vpn/{,*} rw,
|
||||
owner /var/log/private/mullvad-vpn/*.log rw,
|
||||
|
||||
|
||||
@{run}/NetworkManager/resolv.conf r,
|
||||
owner @{run}/mullvad-vpn rw,
|
||||
@{run}/NetworkManager/resolv.conf r,
|
||||
|
||||
@{sys}/fs/cgroup/net_cls/ w,
|
||||
@{sys}/fs/cgroup/net_cls/mullvad-exclusions/ w,
|
||||
|
|
|
|||
|
|
@ -25,14 +25,14 @@ profile ssh-agent-launch @{exec_path} {
|
|||
include <abstractions/bus-session>
|
||||
|
||||
dbus send bus=session path=/org/freedesktop/DBus
|
||||
interface=org.freedesktop.DBus
|
||||
member=UpdateActivationEnvironment
|
||||
peer=(name=org.freedesktop.DBus, label=dbus-session),
|
||||
interface=org.freedesktop.DBus
|
||||
member=UpdateActivationEnvironment
|
||||
peer=(name=org.freedesktop.DBus, label=dbus-session),
|
||||
|
||||
dbus send bus=session path=/org/freedesktop/systemd1
|
||||
interface=org.freedesktop.systemd1.Manager
|
||||
member=SetEnvironment
|
||||
peer=(name=org.freedesktop.systemd1),
|
||||
interface=org.freedesktop.systemd1.Manager
|
||||
member=SetEnvironment
|
||||
peer=(name=org.freedesktop.systemd1),
|
||||
|
||||
@{bin}/dbus-update-activation-environment mr,
|
||||
|
||||
|
|
|
|||
|
|
@ -67,8 +67,8 @@ profile bootctl @{exec_path} {
|
|||
@{sys}/firmware/efi/efivars/SetupMode-@{uuid} r,
|
||||
@{sys}/firmware/efi/fw_platform_size r,
|
||||
|
||||
@{PROC}/sys/kernel/random/poolsize r,
|
||||
owner @{PROC}/@{pid}/cgroup r,
|
||||
@{PROC}/sys/kernel/random/poolsize r,
|
||||
owner @{PROC}/@{pid}/cgroup r,
|
||||
|
||||
# Inherit silencer
|
||||
deny network inet6 stream,
|
||||
|
|
|
|||
|
|
@ -12,7 +12,7 @@ profile systemcheck-canary @{exec_path} {
|
|||
include <abstractions/nameservice-strict>
|
||||
|
||||
@{exec_path} mr,
|
||||
|
||||
|
||||
@{bin}/sleep rix,
|
||||
@{bin}/grep rix,
|
||||
@{bin}/whoami rix,
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue