feat(profile): dbus: Dbus can receive any user files
This commit is contained in:
parent
30999904e7
commit
460ac12bfb
2 changed files with 10 additions and 2 deletions
|
|
@ -18,6 +18,7 @@ profile dbus-session flags=(attach_disconnected) {
|
||||||
include <abstractions/base>
|
include <abstractions/base>
|
||||||
include <abstractions/bus-session>
|
include <abstractions/bus-session>
|
||||||
include <abstractions/consoles>
|
include <abstractions/consoles>
|
||||||
|
include <abstractions/deny-sensitive-home>
|
||||||
include <abstractions/nameservice-strict>
|
include <abstractions/nameservice-strict>
|
||||||
|
|
||||||
network unix stream,
|
network unix stream,
|
||||||
|
|
@ -29,7 +30,7 @@ profile dbus-session flags=(attach_disconnected) {
|
||||||
signal (send) set=(term hup kill) peer=dconf-service,
|
signal (send) set=(term hup kill) peer=dconf-service,
|
||||||
signal (send) set=(term hup kill) peer=xdg-*,
|
signal (send) set=(term hup kill) peer=xdg-*,
|
||||||
|
|
||||||
#aa:dbus own bus=session name=org.freedesktop.DBus path=/{,org/freedesktop/DBus}
|
#aa:dbus own bus=session name=org.freedesktop.DBus path=/{,org/freedesktop/{d,D}Bus}
|
||||||
|
|
||||||
@{exec_path} mrix,
|
@{exec_path} mrix,
|
||||||
|
|
||||||
|
|
@ -49,6 +50,9 @@ profile dbus-session flags=(attach_disconnected) {
|
||||||
/etc/machine-id r,
|
/etc/machine-id r,
|
||||||
/var/lib/dbus/machine-id r,
|
/var/lib/dbus/machine-id r,
|
||||||
|
|
||||||
|
# Dbus can receive any user files
|
||||||
|
owner @{HOME}/** r,
|
||||||
|
|
||||||
owner @{HOME}/.var/app/*/**/.ref rw,
|
owner @{HOME}/.var/app/*/**/.ref rw,
|
||||||
owner @{HOME}/.var/app/*/**/logs/* rw,
|
owner @{HOME}/.var/app/*/**/logs/* rw,
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -15,8 +15,9 @@ include <tunables/global>
|
||||||
@{exec_path} += @{bin}/dbus-daemon @{lib}/dbus-1{,.0}/dbus-daemon-launch-helper
|
@{exec_path} += @{bin}/dbus-daemon @{lib}/dbus-1{,.0}/dbus-daemon-launch-helper
|
||||||
profile dbus-system flags=(attach_disconnected) {
|
profile dbus-system flags=(attach_disconnected) {
|
||||||
include <abstractions/base>
|
include <abstractions/base>
|
||||||
include <abstractions/consoles>
|
|
||||||
include <abstractions/bus-system>
|
include <abstractions/bus-system>
|
||||||
|
include <abstractions/consoles>
|
||||||
|
include <abstractions/deny-sensitive-home>
|
||||||
include <abstractions/nameservice-strict>
|
include <abstractions/nameservice-strict>
|
||||||
|
|
||||||
capability audit_write,
|
capability audit_write,
|
||||||
|
|
@ -53,6 +54,9 @@ profile dbus-system flags=(attach_disconnected) {
|
||||||
@{user_share_dirs}/icc/ r,
|
@{user_share_dirs}/icc/ r,
|
||||||
@{user_share_dirs}/icc/edid-@{hex32}.icc r,
|
@{user_share_dirs}/icc/edid-@{hex32}.icc r,
|
||||||
|
|
||||||
|
# Dbus can receive any user files
|
||||||
|
@{HOME}/** r,
|
||||||
|
|
||||||
@{run}/systemd/inhibit/@{int}.ref rw,
|
@{run}/systemd/inhibit/@{int}.ref rw,
|
||||||
@{run}/systemd/notify w,
|
@{run}/systemd/notify w,
|
||||||
@{run}/systemd/sessions/*.ref rw,
|
@{run}/systemd/sessions/*.ref rw,
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue