child-lsb_release -> lsb_release.

This commit is contained in:
Alexandre Pujol 2021-09-15 16:30:28 +01:00
parent 2a6b2bd189
commit 6c0ae4ddc1
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
32 changed files with 36 additions and 91 deletions

View file

@ -27,7 +27,7 @@ profile atom @{exec_path} {
include <abstractions/deny-dconf>
include <abstractions/deny-root-dir-access>
ptrace (read) peer=child-lsb_release,
ptrace (read) peer=lsb_release,
ptrace (read) peer=xdg-settings,
@{exec_path} mrix,
@ -65,7 +65,7 @@ profile atom @{exec_path} {
/{usr/,}bin/nohup rix,
/{usr/,}bin/cat rix,
/{usr/,}bin/lsb_release rPx -> child-lsb_release,
/{usr/,}bin/lsb_release rPx -> lsb_release,
/{usr/,}bin/xdg-open rCx -> open,
/{usr/,}bin/xdg-settings rPUx,

View file

@ -25,7 +25,7 @@ profile code @{exec_path} {
include <abstractions/deny-dconf>
include <abstractions/deny-root-dir-access>
ptrace (read) peer=child-lsb_release,
ptrace (read) peer=lsb_release,
@{exec_path} mrix,
@ -47,7 +47,7 @@ profile code @{exec_path} {
#/{usr/,}bin/which{,.debianutils} rix,
#/{usr/,}sbin/ifconfig rix,
/{usr/,}bin/lsb_release rPx -> child-lsb_release,
/{usr/,}bin/lsb_release rPx -> lsb_release,
/{usr/,}bin/git rPUx,

View file

@ -117,7 +117,7 @@ profile dropbox @{exec_path} {
# External apps
/{usr/,}bin/xdg-open rCx -> open,
/{usr/,}bin/lsb_release rPx -> child-lsb_release,
/{usr/,}bin/lsb_release rPx -> lsb_release,
# Allowed apps to open
/{usr/,}lib/firefox/firefox rPUx,

View file

@ -27,7 +27,7 @@ profile filezilla @{exec_path} {
# When using SFTP protocol
/{usr/,}bin/fzsftp rPx,
/{usr/,}bin/lsb_release rPx -> child-lsb_release,
/{usr/,}bin/lsb_release rPx -> lsb_release,
owner @{HOME}/ r,
owner @{user_config_dirs}/filezilla/ rw,

View file

@ -166,7 +166,7 @@ profile thunderbird @{exec_path} {
# Silencer
deny /{usr/,}lib/thunderbird/** w,
/{usr/,}bin/lsb_release rPx -> child-lsb_release,
/{usr/,}bin/lsb_release rPx -> lsb_release,
/{usr/,}bin/xdg-open rCx -> open,
/{usr/,}bin/exo-open rCx -> open,
/{usr/,}lib/@{multiarch}/glib-[0-9]*/gio-launch-desktop rCx -> open,

View file

@ -49,7 +49,7 @@ profile apt-listbugs @{exec_path} {
include <abstractions/fontconfig-cache-read>
include <abstractions/freedesktop.org>
capability dac_read_search,
/{usr/,}bin/lsb_release rPx -> child-lsb_release,
/{usr/,}bin/lsb_release rPx -> lsb_release,
/{usr/,}bin/hostname rix,
owner @{PROC}/@{pid}/mounts r,
@{HOME}/.Xauthority r,

View file

@ -68,7 +68,7 @@ profile apt-listchanges @{exec_path} {
include <abstractions/fontconfig-cache-read>
include <abstractions/freedesktop.org>
capability dac_read_search,
/{usr/,}bin/lsb_release rPx -> child-lsb_release,
/{usr/,}bin/lsb_release rPx -> lsb_release,
/{usr/,}bin/hostname rix,
owner @{PROC}/@{pid}/mounts r,
@{HOME}/.Xauthority r,

View file

@ -17,7 +17,7 @@ profile command-not-found @{exec_path} {
@{exec_path} r,
/{usr/,}bin/python3.[0-9]* r,
/{usr/,}bin/lsb_release rPx -> child-lsb_release,
/{usr/,}bin/lsb_release rPx -> lsb_release,
/var/lib/command-not-found/commands.db rwk,

View file

@ -42,7 +42,7 @@ profile dpkg-preconfigure @{exec_path} {
include <abstractions/fontconfig-cache-read>
include <abstractions/freedesktop.org>
capability dac_read_search,
/{usr/,}bin/lsb_release rPx -> child-lsb_release,
/{usr/,}bin/lsb_release rPx -> lsb_release,
/{usr/,}bin/hostname rix,
owner @{PROC}/@{pid}/mounts r,
@{HOME}/.Xauthority r,

View file

@ -54,7 +54,7 @@ profile reportbug @{exec_path} {
#
/{usr/,}{s,}bin/exim4 rPx,
/{usr/,}bin/lsb_release rPx -> child-lsb_release,
/{usr/,}bin/lsb_release rPx -> lsb_release,
/{usr/,}bin/dpkg rPx -> child-dpkg,
/{usr/,}bin/systemctl rPx -> child-systemctl,
/{usr/,}bin/pager rPx -> child-pager,

View file

@ -96,7 +96,7 @@ profile synaptic @{exec_path} {
/{usr/,}sbin/update-command-not-found rPx,
/usr/share/command-not-found/cnf-update-db rPx,
/{usr/,}sbin/update-apt-xapian-index rPx,
/{usr/,}bin/lsb_release rPx -> child-lsb_release,
/{usr/,}bin/lsb_release rPx -> lsb_release,
/{usr/,}bin/deborphan rPx,
/{usr/,}bin/tasksel rPx,
/{usr/,}bin/pkexec rPx,

View file

@ -67,7 +67,7 @@ profile brave @{exec_path} {
# For storing passwords externally
/{usr/,}bin/keepassxc-proxy rPUx,
/{usr/,}bin/lsb_release rPx -> child-lsb_release,
/{usr/,}bin/lsb_release rPx -> lsb_release,
# no new privs
#deny /{usr/,}bin/xdg-desktop-menu rx,

View file

@ -40,7 +40,7 @@ profile chromium-chromium @{exec_path} {
ptrace (trace) peer=@{profile_name},
ptrace (read) peer=xdg-settings,
ptrace (read) peer=keepassxc-proxy,
ptrace (read) peer=child-lsb_release,
ptrace (read) peer=lsb_release,
signal (send) set=(term, kill) peer=keepassxc-proxy,
@ -59,7 +59,7 @@ profile chromium-chromium @{exec_path} {
/{usr/,}bin/keepassxc-proxy rPUx,
/{usr/,}bin/browserpass rPx,
/{usr/,}bin/lsb_release rPx -> child-lsb_release,
/{usr/,}bin/lsb_release rPx -> lsb_release,
/{usr/,}bin/xdg-mime rPUx,
/{usr/,}bin/xdg-open rCx -> open,
/{usr/,}bin/xdg-settings rPUx,

View file

@ -179,7 +179,7 @@ profile firefox @{exec_path} flags=(attach_disconnected) {
/{usr/,}bin/keepassxc-proxy rPUx, # For storing passwords externally
/{usr/,}bin/browserpass rPx,
/{usr/,}bin/lsb_release rPx -> child-lsb_release,
/{usr/,}bin/lsb_release rPx -> lsb_release,
/{usr/,}bin/xdg-open rCx -> open,
/{usr/,}bin/exo-open rCx -> open,

View file

@ -59,7 +59,7 @@ profile google-chrome-chrome @{exec_path} {
# For storing passwords externally
/{usr/,}bin/keepassxc-proxy rPUx,
/{usr/,}bin/lsb_release rPx -> child-lsb_release,
/{usr/,}bin/lsb_release rPx -> lsb_release,
/{usr/,}bin/xdg-open rCx -> open,
# no new privs

View file

@ -55,7 +55,7 @@ profile opera @{exec_path} {
@{OPERA_INSTALLDIR}/opera_crashreporter rPx,
@{OPERA_INSTALLDIR}/opera_autoupdate krix,
/{usr/,}bin/lsb_release rPx -> child-lsb_release,
/{usr/,}bin/lsb_release rPx -> lsb_release,
/{usr/,}bin/xdg-mime rPUx,
/{usr/,}bin/xdg-open rCx -> open,
/{usr/,}bin/xdg-settings rPUx,