feat(profiles): general update.

This commit is contained in:
Alexandre Pujol 2023-08-17 18:43:56 +01:00
parent f7b9ff959a
commit 5d47dfba95
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
50 changed files with 174 additions and 50 deletions

View file

@ -109,8 +109,8 @@ profile pacman @{exec_path} {
@{lib}/ghc-*/bin/ghc-pkg rix,
@{lib}/systemd/systemd-* rPx,
@{lib}/vlc/vlc-cache-gen rPx,
/opt/Mullvad*/resources/mullvad-setup rPx,
/usr/share/code-features/patch.sh rPx,
/usr/share/code-features/patch.py rPx,
/usr/share/code-marketplace/patch.py rPx,
/usr/share/libalpm/scripts/* rPUx,
/usr/share/texmf-dist/scripts/texlive/mktexlsr rPUx,

View file

@ -6,23 +6,21 @@ abi <abi/3.0>,
include <tunables/global>
@{exec_path} = /usr/share/code-features/patch.sh
@{exec_path} = /usr/share/code-{features,marketplace}/patch.py
profile pacman-hook-code @{exec_path} {
include <abstractions/base>
include <abstractions/python>
capability dac_read_search,
@{exec_path} mr,
@{bin}/{,ba}sh rix,
@{bin}/env rix,
@{bin}/grep rix,
@{bin}/sed rix,
@{bin}/python3.[0-9]* rix,
@{lib}/code/product.json rw,
@{lib}/code/sed?????? rw,
/dev/tty rw,
/usr/share/code-{features,marketplace}/* r,
/usr/share/code-{features,marketplace}/cache.json rw,
include if exists <local/pacman-hook-code>
}

View file

@ -14,7 +14,7 @@ profile pacman-hook-mkinitcpio @{exec_path} flags=(attach_disconnected) {
capability dac_read_search,
capability mknod,
# unix (receive) type=stream,
unix (receive) type=stream,
@{exec_path} mr,