feat(tunable): add the user defined private directories

- Add @{XDG_PRIVATE_DIR} & @{user_private_dirs}
- This directories are denied in file browser and search engine.
This commit is contained in:
Alexandre Pujol 2024-05-06 15:19:10 +01:00
parent 8224ac2b3f
commit 3b41ee93dc
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
2 changed files with 9 additions and 4 deletions

View file

@ -39,12 +39,13 @@
deny @{user_password_store_dirs}/{,**} mrwkl,
deny @{user_share_dirs}/kwalletd/{,**} mrwkl,
# User defined private directories
deny @{user_private_dirs}/** mrxwlk,
deny @{HOMEDIRS}/**/@{XDG_PRIVATE_DIR}/** mrxwlk,
deny @{MOUNTS}/**/@{XDG_PRIVATE_DIR}/** mrxwlk,
# Deny executable mapping in writable space as allowed in abstractions/fonts
deny @{HOME}/.{,cache/}fontconfig/ rw,
deny @{HOME}/.{,cache/}fontconfig/** mrwl,
# Deny executable mapping in writable space as allowed in abstractions/base for ecryptfs
deny @{HOME}/.Private/** mrxwlk,
deny @{HOMEDIRS}/.ecryptfs/*/.Private/** mrxwlk,
include if exists <abstractions/deny-sensitive-home.d>