Replace shells with new sh_path variable

Signed-off-by: Jeroen Rijken <jeroen.rijken@xs4all.nl>
This commit is contained in:
Jeroen Rijken 2024-02-11 15:34:46 +01:00 committed by Alex
parent 3b1b187d13
commit 40b171ee94
315 changed files with 415 additions and 369 deletions

View file

@ -12,7 +12,7 @@ profile sanoid @{exec_path} flags=(complain) {
include <abstractions/perl>
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/perl rix,
@{bin}/ps rPx,
/{usr/,}{local/,}{s,}bin/zfs rPx,

View file

@ -15,7 +15,7 @@ profile scrot @{exec_path} {
@{exec_path} mr,
# "mv" is needed to change the image dir
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/mv rix,
# The image dir

View file

@ -20,7 +20,7 @@ profile secure-time-sync @{exec_path} flags=(attach_disconnected) {
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/curl rix,
@{bin}/date rix,
@{bin}/grep rix,

View file

@ -22,7 +22,7 @@ profile smartd @{exec_path} {
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/cat rix,
@{bin}/hostname rix,
@{bin}/mail rix,

View file

@ -87,7 +87,7 @@ profile smtube @{exec_path} {
@{bin}/xdg-open mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/{m,g,}awk rix,
@{bin}/readlink rix,
@{bin}/basename rix,

View file

@ -66,7 +66,7 @@ profile snapd @{exec_path} {
@{bin}/ssh-keygen rPx,
@{bin}/useradd rPx,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/apparmor_parser rPx,
@{bin}/cp rix,
@{bin}/gzip rix,

View file

@ -12,7 +12,7 @@ profile spacefm-auth @{exec_path} {
include <abstractions/base>
@{exec_path} r,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
include if exists <local/spacefm-auth>
}

View file

@ -28,7 +28,7 @@ profile spectre-meltdown-checker @{exec_path} {
@{bin}/{,@{multiarch}-}objdump rix,
@{bin}/{,@{multiarch}-}readelf rix,
@{bin}/{,@{multiarch}-}strings rix,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/{,e}grep rix,
@{bin}/{,g,m}awk rix,
@{bin}/base64 rix,

View file

@ -12,7 +12,7 @@ profile start-pulseaudio-x11 @{exec_path} {
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/head rix,
@{bin}/pactl rPx,
@{bin}/plasmashell rPx,

View file

@ -14,7 +14,7 @@ profile startx @{exec_path} flags=(attach_disconnected) {
include <abstractions/nameservice-strict>
@{exec_path} r,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/{,e}grep rix,
@{bin}/deallocvt rix,

View file

@ -37,7 +37,7 @@ profile steam @{exec_path} flags=(attach_disconnected,mediate_deleted,complain)
@{exec_path} mrix,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/{m,g,}awk rix,
@{bin}/*sum rix,
@{bin}/basename rix,

View file

@ -60,7 +60,7 @@ profile steam-game @{exec_path} flags=(attach_disconnected) {
@{exec_path} mrix,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/bwrap rix,
@{bin}/env rix,
@{bin}/getopt rix,

View file

@ -111,7 +111,7 @@ profile strawberry @{exec_path} {
@{bin}/xdg-open mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/{m,g,}awk rix,
@{bin}/readlink rix,
@{bin}/basename rix,

View file

@ -14,7 +14,7 @@ profile syncoid @{exec_path} flags=(complain) {
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/grep rix,
@{bin}/mbuffer rix,
@{bin}/perl rix,

View file

@ -31,7 +31,7 @@ profile system-config-printer @{exec_path} flags=(complain) {
@{exec_path} mrix,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/python3.@{int} r,
@{lib}/cups/*/* rPUx,
/usr/share/hplip/query.py rPUx,

View file

@ -19,7 +19,7 @@ profile system-config-printer-applet @{exec_path} {
@{exec_path} mrix,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/python3.@{int} r,
/usr/share/system-config-printer/{,**} r,

View file

@ -15,7 +15,7 @@ profile tasksel @{exec_path} flags=(complain) {
@{exec_path} r,
@{bin}/perl r,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/tempfile rix,
@{lib}/tasksel/tasksel-debconf rix,
@ -45,7 +45,7 @@ profile tasksel @{exec_path} flags=(complain) {
include <abstractions/base>
@{lib}/tasksel/tests/* r,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
}
@ -60,7 +60,7 @@ profile tasksel @{exec_path} flags=(complain) {
@{bin}/tasksel rPx,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/stty rix,
@{bin}/locale rix,

View file

@ -59,7 +59,7 @@ profile thunderbird @{exec_path} {
@{exec_path} mrix,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{lib_dirs}/{,**} r,
@{lib_dirs}/*.so mr,

View file

@ -19,7 +19,7 @@ profile tint2conf @{exec_path} {
@{bin}/tint2 rPx,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
/usr/share/tint2/{,*} r,

View file

@ -12,7 +12,7 @@ profile torify @{exec_path} {
include <abstractions/base>
@{exec_path} r,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
include if exists <local/torify>
}

View file

@ -16,7 +16,7 @@ profile torsocks @{exec_path} {
@{exec_path} rm,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/* rPUx,
@{lib}/uwt/uwtexec rPUx,
@{bin}/getcap rix,

View file

@ -15,7 +15,7 @@ profile tpacpi-bat @{exec_path} {
@{exec_path} mr,
@{bin}/perl r,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/cat rix,
# To load the acpi_call module

View file

@ -13,7 +13,7 @@ profile ucf @{exec_path} flags=(complain) {
include <abstractions/consoles>
@{exec_path} r,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/{,e}grep rix,
@{bin}/basename rix,
@ -92,7 +92,7 @@ profile ucf @{exec_path} flags=(complain) {
@{bin}/ucf rPx,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/stty rix,
@{bin}/locale rix,

View file

@ -49,7 +49,7 @@ profile udiskie @{exec_path} {
@{bin}/xdg-open mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/{m,g,}awk rix,
@{bin}/readlink rix,
@{bin}/basename rix,

View file

@ -13,7 +13,7 @@ profile udisksctl @{exec_path} {
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/pager rPx -> child-pager,
@{bin}/less rPx -> child-pager,

View file

@ -69,7 +69,7 @@ profile udisksd @{exec_path} flags=(attach_disconnected) {
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/umount rix,
@{bin}/dmidecode rPx,

View file

@ -18,7 +18,7 @@ profile unhide-linux @{exec_path} {
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/ps rix,
@{PROC}/ r,

View file

@ -18,7 +18,7 @@ profile unhide-posix @{exec_path} {
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/{,e}grep rix,
@{bin}/{m,g,}awk rix,
@{bin}/ps rix,

View file

@ -18,7 +18,7 @@ profile unhide-tcp @{exec_path} {
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/fuser rix,
@{bin}/netstat rix,
@{bin}/sed rix,

View file

@ -17,7 +17,7 @@ profile unmkinitramfs @{exec_path} {
@{exec_path} r,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/{,e}grep rix,
@{bin}/bzip2 rix,
@{bin}/cat rix,

View file

@ -16,7 +16,7 @@ profile update-ca-certificates @{exec_path} {
@{exec_path} rmix,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/basename rix,
@{bin}/cat rix,
@{bin}/chmod rix,

View file

@ -13,7 +13,7 @@ profile update-cracklib @{exec_path} {
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/cracklib-format rix,
@{bin}/cracklib-packer rPx,
@{bin}/env rix,

View file

@ -13,7 +13,7 @@ profile update-dlocatedb @{exec_path} {
include <abstractions/consoles>
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/cat rix,
@{bin}/uname rix,

View file

@ -15,7 +15,7 @@ profile update-initramfs @{exec_path} {
ptrace (read) peer=unconfined,
@{exec_path} rix,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/ r,

View file

@ -13,7 +13,7 @@ profile update-pciids @{exec_path} {
include <abstractions/consoles>
@{exec_path} r,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/touch rix,
@{bin}/rm rix,

View file

@ -14,7 +14,7 @@ profile update-secureboot-policy @{exec_path} {
@{exec_path} rm,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/{,m,g}awk rix,
@{bin}/dpkg-trigger rPx,
@{bin}/find rix,

View file

@ -13,7 +13,7 @@ profile update-smart-drivedb @{exec_path} {
include <abstractions/consoles>
@{exec_path} r,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/cat rix,
@{bin}/dirname rix,
@ -76,7 +76,7 @@ profile update-smart-drivedb @{exec_path} {
@{bin}/curl mr,
@{bin}/lynx mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
/etc/mime.types r,
/etc/mailcap r,

View file

@ -17,7 +17,7 @@ profile usb-devices @{exec_path} {
deny capability dac_override,
@{exec_path} r,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/cat rix,
@{bin}/cut rix,

View file

@ -45,7 +45,7 @@ profile utox @{exec_path} {
@{bin}/xdg-open mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/{m,g,}awk rix,
@{bin}/readlink rix,
@{bin}/basename rix,

View file

@ -15,7 +15,7 @@ profile uupdate @{exec_path} flags=(complain) {
include <abstractions/nameservice-strict>
@{exec_path} r,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/basename rix,
@{bin}/which{,.debianutils} rix,

View file

@ -15,7 +15,7 @@ profile vipw-vigr @{exec_path} {
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/sensible-editor rCx -> editor,
@{bin}/vim.* rCx -> editor,
@ -47,7 +47,7 @@ profile vipw-vigr @{exec_path} {
@{bin}/sensible-editor mr,
@{bin}/vim.* mrix,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/which{,.debianutils} rix,
owner @{HOME}/.selected_editor r,

View file

@ -31,7 +31,7 @@ profile virt-manager @{exec_path} flags=(attach_disconnected) {
@{exec_path} rix,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/python3.@{int} r,
@{lib}/python3.@{int}/site-packages/__pycache__/guestfs.cpython-[0-9]*.pyc.[0-9]* w,

View file

@ -34,7 +34,7 @@ profile volumeicon @{exec_path} {
/etc/machine-id r,
# Start the PulseAudio sound mixer
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/pavucontrol rPUx,
@{bin}/pulseeffects rPUx,

View file

@ -19,7 +19,7 @@ profile whdd @{exec_path} {
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/{,e}grep rix,
@{bin}/{m,g,}awk rix,
@{bin}/tr rix,

View file

@ -14,7 +14,7 @@ profile which @{exec_path} flags=(attach_disconnected) {
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/ r,
@{bin}/**/ r,

View file

@ -94,7 +94,7 @@ profile wireshark @{exec_path} {
@{bin}/xdg-open mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/{m,g,}awk rix,
@{bin}/readlink rix,
@{bin}/basename rix,

View file

@ -19,7 +19,7 @@ profile wpa-action @{exec_path} {
@{bin}/wpa_cli rPx,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/{,e}grep rix,
@{bin}/cat rix,
@{bin}/date rix,

View file

@ -15,7 +15,7 @@ profile x11-xsession @{exec_path} {
@{exec_path} r,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/{,e}grep rix,
@{bin}/{m,g,}awk rix,
@{bin}/basename rix,

View file

@ -21,7 +21,7 @@ profile xarchiver @{exec_path} {
@{exec_path} mrix,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/ls rix,
@{bin}/rm rix,
@{bin}/mv rix,
@ -79,7 +79,7 @@ profile xarchiver @{exec_path} {
@{bin}/xdg-open mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/{m,g,}awk rix,
@{bin}/readlink rix,
@{bin}/basename rix,

View file

@ -13,7 +13,7 @@ profile xautolock @{exec_path} {
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/env rix,
# Locker apps to launch.

View file

@ -20,7 +20,7 @@ profile xinit @{exec_path} {
@{exec_path} mr,
@{bin}/ r,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/{,e}grep rix,
@{bin}/{m,g,}awk rix,
@{bin}/cat rix,

View file

@ -27,7 +27,7 @@ profile youtube-viewer @{exec_path} {
@{exec_path} r,
@{bin}/perl r,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/infocmp rix,
@{bin}/stty rix,

View file

@ -15,7 +15,7 @@ profile zpool @{exec_path} {
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
/{usr/,}{local/,}lib/zfs-linux/zpool.d/* rix,
/etc/hostid r,

View file

@ -13,7 +13,7 @@ profile zsys-system-autosnapshot @{exec_path} flags=(complain) {
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{sh_path} rix,
@{bin}/cat rix,
@{bin}/cp rix,
@{bin}/rm rix,