From a9a41ef810d97d0ffcf3d42e4d7ab4bb287da52e Mon Sep 17 00:00:00 2001 From: Alexandre Pujol Date: Fri, 1 Nov 2024 11:59:30 +0100 Subject: [PATCH 1/3] feat(profile): pacman can restart any updated program. See #596 --- apparmor.d/groups/pacman/pacman | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apparmor.d/groups/pacman/pacman b/apparmor.d/groups/pacman/pacman index 1c7015b1f..8215e3f6a 100644 --- a/apparmor.d/groups/pacman/pacman +++ b/apparmor.d/groups/pacman/pacman @@ -39,7 +39,7 @@ profile pacman @{exec_path} flags=(attach_disconnected) { ptrace read, - signal send set=usr1 peer=gvfsd, + signal send, signal receive set=winch peer=makepkg//sudo, @{exec_path} mrix, From 1eb7be5447a6603ca28faa33a23e2d32af97f64e Mon Sep 17 00:00:00 2001 From: Roman Beslik Date: Sun, 3 Nov 2024 16:53:56 +0200 Subject: [PATCH 2/3] /boot/EFI 2 --- apparmor.d/groups/pacman/mkinitcpio | 6 +++--- apparmor.d/groups/pacman/pacman-hook-mkinitcpio | 2 +- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/apparmor.d/groups/pacman/mkinitcpio b/apparmor.d/groups/pacman/mkinitcpio index dcf5b10fb..ed91f6c9c 100644 --- a/apparmor.d/groups/pacman/mkinitcpio +++ b/apparmor.d/groups/pacman/mkinitcpio @@ -83,10 +83,10 @@ profile mkinitcpio @{exec_path} flags=(attach_disconnected) { # Manage /boot / r, - /{boot,efi}/ r, + /boot/ r, /{boot,efi}/EFI/{,**} rw, - /{boot,efi}/initramfs-*.img* rw, - /{boot,efi}/vmlinuz-* r, + /boot/initramfs-*.img* rw, + /boot/vmlinuz-* r, /usr/share/systemd/bootctl/** r, diff --git a/apparmor.d/groups/pacman/pacman-hook-mkinitcpio b/apparmor.d/groups/pacman/pacman-hook-mkinitcpio index 9ee488fbc..a9bf40360 100644 --- a/apparmor.d/groups/pacman/pacman-hook-mkinitcpio +++ b/apparmor.d/groups/pacman/pacman-hook-mkinitcpio @@ -37,7 +37,7 @@ profile pacman-hook-mkinitcpio @{exec_path} flags=(attach_disconnected) { / r, /boot/ r, - /boot/efi/boot/boot*.efi rw, + /{boot,efi}/EFI/boot/boot*.efi rw, /boot/initramfs-*-fallback.img rw, /boot/initramfs-*.img rw, /boot/vmlinuz-* rw, From 026fbf75520b3f20160c058936275354f1ecc652 Mon Sep 17 00:00:00 2001 From: Besanon Date: Mon, 4 Nov 2024 11:21:08 +0100 Subject: [PATCH 3/3] Add lxqt-panel (#594) --- apparmor.d/groups/lxqt/lxqt-panel | 92 +++++++++++++++++++++++++++++++ 1 file changed, 92 insertions(+) create mode 100644 apparmor.d/groups/lxqt/lxqt-panel diff --git a/apparmor.d/groups/lxqt/lxqt-panel b/apparmor.d/groups/lxqt/lxqt-panel new file mode 100644 index 000000000..650a7e402 --- /dev/null +++ b/apparmor.d/groups/lxqt/lxqt-panel @@ -0,0 +1,92 @@ +# apparmor.d - Full set of apparmor profiles +# Copyright (C) 2024 Alexandre Pujol +# Copyright (C) 2024 Besanon +# SPDX-License-Identifier: GPL-2.0-only + +abi , + +include + +@{exec_path} = @{bin}/lxqt-panel +profile lxqt-panel @{exec_path} { + include + include + include + include + include + + network inet dgram, + network inet6 dgram, + network inet stream, + network inet6 stream, + network netlink raw, + network packet dgram, + + @{exec_path} mr, + + @{bin}/exo-open rix, + @{lib}/gio-launch-desktop rix, + @{bin}/nm-applet rPx, + @{bin}/nm-connection-editor rPx, + @{bin}/ControlPanel rPx, + + @{bin}/sudo rCx -> root, + + @{lib}/lxqt-panel/*.so mr, # LXQT-Plugins + @{lib}/lxqt-config/*.so mr, # LXQT-Plugins + + /usr/share/desktop-directories/{,**} r, + /usr/share/lxqt/{,**} r, + + /etc/fstab r, + /etc/udev/udev.conf r, + /etc/machine-id r, + /etc/xdg/lxqt-qtxdg.conf r, + /etc/xdg/menus/**.menu r, + /etc/xdg/menus/applications-merged/ r, + /etc/xdg/ui/uistandards.rc r, + + /var/lib/dbus/machine-id r, + + owner @{HOME}/Desktop/*.desktop rw, + owner @{HOME}/Desktop/#@{int} rw, + owner @{HOME}/Desktop/*.desktop l -> @{HOME}/Desktop/#@{int}, + + owner @{user_config_dirs}/menus/*.menu rw, + owner @{user_config_dirs}/menus/applications-merged/ r, + owner @{user_config_dirs}/share/desktop-directories/*.directory r, + owner @{user_config_dirs}/share/gvfs-metadata/{,*} r, + owner @{user_config_dirs}/lxqt/#@{int} rw, + owner @{user_config_dirs}/lxqt/panel.conf rw, + owner @{user_config_dirs}/lxqt/panel.conf.lock rwk, + owner @{user_config_dirs}/lxqt/panel.conf.@{rand6} rw, + owner @{user_config_dirs}/lxqt/panel.conf.@{rand6} l -> @{user_config_dirs}/lxqt/#@{int}, + owner @{user_config_dirs}/pulse/{,**} rwk, + + @{run}/udev/data/* r, + + @{sys}/class/i2c-adapter/ r, + @{sys}/devices/system/cpu/cpufreq/policy@{int}/scaling_{cur,min,max}_freq r, + + @{PROC}/@{pid}/fd/ r, + @{PROC}/@{pid}/net/dev r, + owner @{PROC}/@{pid}/mounts r, + + /dev/tty rw, + /dev/tty@{int} rw, + /dev/pts/@{int} rw, + /dev/snd/controlC@{int} rw, + + profile root { + include + include + + @{bin}/lsblk rPx, + + include if exists + } + + include if exists +} + +# vim:syntax=apparmor