Unbreak Debian 11 and partially Ubuntu 22.04 (Wayland+GDM+Gnome) (#81)

* Unbreaking Debian 11 and partially Ubuntu 22.04

* pre-cleanup

* pre-cleanup2

* Update im-launch

* Update gnome-extension-ding

* polishing

* not yet

* Update ubuntu.flags

Allow GDM to boot. `No new privs` fix.

* Update debian.flags

Allow GDM to boot. `No new privs` fix.

* Update CONTRIBUTING.md

* fixes

* reverting w

* move setpriv to main.flags
This commit is contained in:
nobodysu 2022-10-14 21:21:56 +00:00 committed by GitHub
parent bdcaa040fe
commit 643a84997e
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
110 changed files with 3157 additions and 182 deletions

View file

@ -29,7 +29,7 @@ profile scrcpy @{exec_path} {
/var/lib/dbus/machine-id r,
owner @{user_config_dirs}/ibus/bus/{,@{hex}-unix-wayland-[0-9]} r,
owner @{user_config_dirs}/ibus/bus/{,@{hex}-unix{,-wayland}-[0-9]} r,
include if exists <local/scrcpy>
}
}

View file

@ -14,6 +14,13 @@ profile snap @{exec_path} {
include <abstractions/dbus-strict>
include <abstractions/nameservice-strict>
unix (send, receive) type=stream peer=(label=apt),
dbus send bus=session path=/org/freedesktop/portal/documents
interface=org.freedesktop.portal.Documents
member=GetMountPoint
peer=(name=org.freedesktop.portal.Documents),
@{exec_path} mrix,
/snap/{,**} rw,
@ -23,11 +30,14 @@ profile snap @{exec_path} {
/etc/fstab r,
/var/lib/snapd/{,**} rwk,#
/var/lib/snapd/{,**} rwk,
/var/cache/snapd/commands.db rwk,
owner @{HOME}/snap/{,**} rw,
owner @{run}/user/@{uid}/.mutter-Xwaylandauth.[0-9A-Z]* r,
owner @{run}/user/@{uid}/gdm/Xauthority r,
owner @{run}/user/@{uid}/systemd/notify rw,
@{run}/snapd.socket rw,
@ -46,4 +56,4 @@ profile snap @{exec_path} {
deny @{user_share_dirs}/gvfs-metadata/* r,
include if exists <local/snap>
}
}

View file

@ -11,18 +11,40 @@ profile spice-vdagent @{exec_path} {
include <abstractions/base>
include <abstractions/audio>
include <abstractions/dbus-session-strict>
include <abstractions/dbus-accessibility-strict>
include <abstractions/fonts>
include <abstractions/gtk>
include <abstractions/X-strict>
dbus send bus=session path=/org/gnome/Mutter/DisplayConfig
interface=org.gnome.Mutter.DisplayConfig
member=GetCurrentState
peer=(name=:*, label=gnome-shell),
dbus send bus=session path=/org/a11y/bus
interface=org.a11y.Bus
member=GetAddress
peer=(name=org.a11y.Bus),
peer=(name=org.a11y.Bus, label=at-spi-bus-launcher),
dbus send bus=session path=/org/gnome/Mutter/DisplayConfig
interface=org.gnome.Mutter.DisplayConfig
member=GetCurrentState,
dbus receive bus=accessibility path=/org/a11y/atspi/registry
interface=org.a11y.atspi.Registry
member=EventListenerDeregistered
peer=(name=:*, label=at-spi2-registryd),
dbus send bus=accessibility path=/org/a11y/atspi/registry
interface=org.a11y.atspi.Registry
member=GetRegisteredEvents
peer=(name=org.a11y.atspi.Registry), # all peer's labels
dbus send bus=accessibility path=/org/a11y/atspi/registry/deviceeventcontroller
interface=org.a11y.atspi.DeviceEventController
member={GetKeystrokeListeners,GetDeviceEventListeners}
peer=(name=org.a11y.atspi.Registry), # all peer's labels
dbus send bus=accessibility path=/org/a11y/atspi/accessible/root
interface=org.a11y.atspi.Socket
member=Embed
peer=(name=org.a11y.atspi.Registry), # all peer's labels
@{exec_path} mr,
@ -37,4 +59,4 @@ profile spice-vdagent @{exec_path} {
/dev/dri/card[0-9]* rw,
include if exists <local/spice-vdagent>
}
}

View file

@ -37,7 +37,7 @@ profile switcheroo-control @{exec_path} flags=(attach_disconnected) {
@{sys}/class/ r,
@{sys}/class/drm/ r,
@{sys}/devices/pci[0-9]*/**/boot_vga r,
@{sys}/devices/pci[0-9]*/**/uevent r,
@{sys}/devices/{pci[0-9]*,virtual}/**/uevent r,
include if exists <local/switcheroo-control>
}
}

View file

@ -64,6 +64,11 @@ profile udisksd @{exec_path} flags=(attach_disconnected) {
interface=org.freedesktop.login[0-9].Manager
member=Inhibit,
dbus receive bus=system path=/org/freedesktop/login[0-9]*
interface=org.freedesktop.login[0-9]*.Manager
member={PrepareForSleep,PrepareForShutdown}
peer=(name=:*, label=systemd-logind),
dbus send bus=system path=/org/freedesktop/PolicyKit[0-9]/Authority
interface=org.freedesktop.DBus.Properties
member=GetAll,

View file

@ -36,7 +36,7 @@ profile useradd @{exec_path} {
@{exec_path} mr,
/{usr/,}bin/usermod rPx,
/{usr/,}{s,}bin/usermod rPx,
/{usr/,}{s,}bin/pam_tally2 rCx -> pam_tally2,
@ -81,6 +81,7 @@ profile useradd @{exec_path} {
/var/log/tallylog rw,
include if exists <local/useradd_pam_tally2>
}
include if exists <local/useradd>