Profiles update.

This commit is contained in:
Alexandre Pujol 2022-03-17 14:01:50 +00:00
parent bb0847f5df
commit 4ff371e739
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
22 changed files with 67 additions and 33 deletions

View file

@ -12,6 +12,7 @@ profile evolution-alarm-notify @{exec_path} {
include <abstractions/fontconfig-cache-read>
include <abstractions/gnome>
include <abstractions/nameservice-strict>
include <abstractions/opencl>
include <abstractions/openssl>
@{exec_path} mr,

View file

@ -57,6 +57,8 @@ profile gjs-console @{exec_path} flags=(attach_disconnected) {
@{run}/user/@{uid}/wayland-cursor-shared-* rw,
@{sys}/devices/pci[0-9]*/**/drm/ r,
@{sys}/devices/pci[0-9]*/**/drm/card[0-9]*/**/id r,
@{sys}/devices/pci[0-9]*/**/drm/card[0-9]*/gt_*_mhz r,
/dev/ r,
/dev/tty rw,

View file

@ -11,6 +11,7 @@ profile gnome-calendar @{exec_path} {
include <abstractions/base>
include <abstractions/gnome>
include <abstractions/nameservice-strict>
include <abstractions/opencl>
include <abstractions/openssl>
include <abstractions/p11-kit>
include <abstractions/ssl_certs>

View file

@ -9,6 +9,7 @@ include <tunables/global>
@{exec_path} = /{usr/,}lib/gnome-contacts-search-provider
profile gnome-contacts-search-provider @{exec_path} {
include <abstractions/base>
include <abstractions/opencl>
include <abstractions/openssl>
signal (send) set=(term) peer=unconfined,

View file

@ -10,6 +10,7 @@ include <tunables/global>
profile goa-daemon @{exec_path} {
include <abstractions/base>
include <abstractions/nameservice-strict>
include <abstractions/opencl>
include <abstractions/openssl>
include <abstractions/p11-kit>
include <abstractions/ssl_certs>

View file

@ -15,6 +15,7 @@ profile gsd-xsettings @{exec_path} {
include <abstractions/fonts>
include <abstractions/gtk>
include <abstractions/nameservice-strict>
include <abstractions/opencl>
network inet stream,
network inet6 stream,

View file

@ -28,6 +28,7 @@ profile nautilus @{exec_path} flags=(attach_disconnected) {
# Full access to user's data
/ r,
/home/ r,
owner @{HOME}/{,**} rw,
owner @{MOUNTS}/{,**} rw,
owner @{run}/user/@{uid}/{,**} rw,
@ -46,7 +47,7 @@ profile nautilus @{exec_path} flags=(attach_disconnected) {
owner @{PROC}/@{pid}/fd/ r,
owner @{PROC}/@{pid}/mountinfo r,
owner @{PROC}/@{pid}/net/wireless r,
@{PROC}/@{pids}/net/wireless r,
@{run}/mount/utab r,
@{run}/systemd/userdb/ r,