feat(profile): cleanup common desktop files.

This commit is contained in:
Alexandre Pujol 2024-03-21 23:28:57 +00:00
parent 0d16d4fdab
commit 87db46113c
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
13 changed files with 18 additions and 53 deletions

View file

@ -89,8 +89,6 @@ profile pulseaudio @{exec_path} {
/etc/pulse/{,**} r,
/var/lib/snapd/desktop/applications/ r,
owner @{desktop_cache_dirs}/gstreamer-1.0/ rw,
owner @{desktop_cache_dirs}/gstreamer-1.0/registry.*.bin{,.tmp@{rand6}} rw,
owner @{desktop_config_dirs}/dconf/user r,

View file

@ -11,26 +11,19 @@ include <tunables/global>
profile update-desktop-database @{exec_path} flags=(attach_disconnected) {
include <abstractions/base>
include <abstractions/consoles>
include <abstractions/freedesktop.org>
capability dac_override,
capability dac_read_search,
@{exec_path} mr,
/usr/share/{,ubuntu/}applications/{,**/} r,
/usr/share/{,ubuntu/}applications/**.desktop r,
/usr/share/{,ubuntu/}applications/.mimeinfo.cache.* rw,
/usr/share/{,ubuntu/}applications/mimeinfo.cache w,
@{system_share_dirs}/*ubuntu/applications/.mimeinfo.cache.* rw,
@{system_share_dirs}/*ubuntu/applications/mimeinfo.cache w,
/usr/share/*/*.desktop r,
@{system_share_dirs}/applications/.mimeinfo.cache.* rw,
@{system_share_dirs}/applications/mimeinfo.cache w,
/var/lib/flatpak/{app/**/,}export{s,}/share/applications/{,**/} r,
/var/lib/flatpak/{app/**/,}export{s,}/share/applications/**.desktop r,
/var/lib/flatpak/{app/**/,}export{s,}/share/applications/.mimeinfo.cache.* rw,
/var/lib/flatpak/{app/**/,}export{s,}/share/applications/mimeinfo.cache w,
/var/lib/snapd/desktop/applications/{,**/} r,
/var/lib/snapd/desktop/applications/**.desktop r,
/var/lib/snapd/desktop/applications/.mimeinfo.cache.* rw,
/var/lib/snapd/desktop/applications/mimeinfo.cache w,

View file

@ -11,6 +11,7 @@ include <tunables/global>
profile xdg-settings @{exec_path} {
include <abstractions/base>
include <abstractions/consoles>
include <abstractions/freedesktop.org>
@{exec_path} r,
@ -41,15 +42,6 @@ profile xdg-settings @{exec_path} {
/etc/machine-id r,
/var/lib/dbus/machine-id r,
/var/lib/flatpak/exports/share/applications/{,*} r,
/var/lib/snapd/desktop/applications/{,*} r,
# freedesktop.org-strict
/usr/{,local/}share/applications/{,*} r,
/usr/{,local/}share/ubuntu/applications/ r,
owner @{user_share_dirs}/applications/ r,
owner @{user_share_dirs}/applications/*.desktop r,
owner @{HOME}/ r,
owner @{HOME}/.Xauthority r,

View file

@ -52,9 +52,6 @@ profile gnome-terminal-server @{exec_path} {
/etc/shells r,
/var/lib/flatpak/exports/share/icons/{,**} r,
/var/lib/snapd/desktop/icons/{,**} r,
owner @{user_config_dirs}/*xdg-terminals.list* rw,
owner @{user_config_dirs}/ibus/bus/ r,
owner @{user_config_dirs}/ibus/bus/@{hex32}-unix-{,wayland-}@{int} r,

View file

@ -43,9 +43,6 @@ profile tracker-miner @{exec_path} flags=(attach_disconnected) {
/etc/blkid.conf r,
/etc/timezone r,
/var/lib/flatpak/exports/share/applications/{,mimeinfo.cache} r,
/var/lib/snapd/desktop/applications/{,mimeinfo.cache} r,
owner @{GDM_HOME}/ r,
owner @{GDM_HOME}/greeter-dconf-defaults r,
owner @{gdm_cache_dirs}/gstreamer-*/registry.*.bin r,

View file

@ -71,7 +71,6 @@ profile software-properties-gtk @{exec_path} {
/etc/update-manager/release-upgrades r,
/var/crash/*software-properties-gtk.@{uid}.crash rw,
/var/lib/snapd/desktop/icons/ r,
/var/lib/ubuntu-advantage/status.json r,
owner /tmp/???????? rw,

View file

@ -66,8 +66,6 @@ profile update-manager @{exec_path} flags=(attach_disconnected) {
/var/lib/dpkg/info/*.list r,
/var/lib/dpkg/updates/ r,
/var/lib/snapd/desktop/applications/{,mimeinfo.cache} r,
/var/lib/snapd/desktop/icons/{,*} r,
/var/lib/update-manager/{,**} rw,
owner @{user_cache_dirs}/update-manager-core/{,**} rw,