Update profiles.
This commit is contained in:
parent
7274f98fa6
commit
9ecc1aa240
10 changed files with 33 additions and 14 deletions
|
|
@ -20,8 +20,10 @@ profile ibus-portal @{exec_path} flags=(attach_disconnected) {
|
|||
/usr/share/locale/locale.alias r,
|
||||
|
||||
/var/lib/dbus/machine-id r,
|
||||
/var/lib/gdm/.config/ibus/bus/{,[0-9a-f]*-unix-wayland-[0-9]} r,
|
||||
owner @{user_config_dirs}/ibus/bus/{,[0-9a-f]*-unix-wayland-[0-9]} r,
|
||||
/var/lib/gdm/.config/ibus/bus/ r,
|
||||
/var/lib/gdm/.config/ibus/bus/[0-9a-f]*-unix-{,wayland-}[0-9] r,
|
||||
owner @{user_config_dirs}/ibus/bus/ r,
|
||||
owner @{user_config_dirs}/ibus/bus/[0-9a-f]*-unix-{,wayland-}[0-9] r,
|
||||
|
||||
owner /dev/tty[0-9]* rw,
|
||||
/dev/null rw,
|
||||
|
|
|
|||
|
|
@ -17,6 +17,7 @@ profile gnome-control-center-print-renderer @{exec_path} {
|
|||
|
||||
@{exec_path} mr,
|
||||
|
||||
/usr/share/egl/{,**} r,
|
||||
/usr/share/glib-2.0/schemas/gschemas.compiled r,
|
||||
/usr/share/glvnd/egl_vendor.d/{,*.json} r,
|
||||
/usr/share/icons/{,**} r,
|
||||
|
|
@ -25,6 +26,7 @@ profile gnome-control-center-print-renderer @{exec_path} {
|
|||
/usr/share/X11/xkb/** r,
|
||||
|
||||
owner @{user_cache_dirs}/mesa_shader_cache/index rw,
|
||||
owner @{user_share_dirs}/icons/{,**} r,
|
||||
|
||||
owner @{run}/user/@{uid}/gdm/Xauthority r,
|
||||
|
||||
|
|
|
|||
|
|
@ -27,7 +27,7 @@ profile nautilus @{exec_path} flags=(attach_disconnected) {
|
|||
# Full access to user's data
|
||||
/ r,
|
||||
owner @{HOME}/{,**} rw,
|
||||
owner @{MOUNTS}/*/{,**} rw,
|
||||
owner @{MOUNTS}/{,**} r,
|
||||
owner @{run}/user/@{uid}/{,**} rw,
|
||||
owner /tmp/{,**} rw,
|
||||
|
||||
|
|
|
|||
|
|
@ -10,9 +10,17 @@ include <tunables/global>
|
|||
profile systemd-makefs @{exec_path} {
|
||||
include <abstractions/base>
|
||||
|
||||
capability net_admin,
|
||||
capability sys_resource,
|
||||
|
||||
@{exec_path} mr,
|
||||
|
||||
/{usr/,}{s,}bin/mkswap rPx,
|
||||
|
||||
@{sys}/devices/virtual/block/zram[0-9]*/ r,
|
||||
@{sys}/devices/virtual/block/zram[0-9]*/** r,
|
||||
|
||||
/dev/zram[0-9]* rwk,
|
||||
|
||||
include if exists <local/systemd-makefs>
|
||||
}
|
||||
|
|
@ -15,17 +15,17 @@ profile systemd-udevd @{exec_path} flags=(attach_disconnected complain) {
|
|||
include <abstractions/consoles>
|
||||
include <abstractions/systemd-common>
|
||||
|
||||
# (##FIXME##)
|
||||
capability sys_admin,
|
||||
capability net_admin,
|
||||
capability dac_read_search,
|
||||
capability chown,
|
||||
capability dac_override,
|
||||
capability dac_read_search,
|
||||
capability fowner,
|
||||
capability fsetid,
|
||||
capability mknod,
|
||||
capability net_admin,
|
||||
capability sys_admin,
|
||||
capability sys_module,
|
||||
capability sys_ptrace,
|
||||
capability sys_resource,
|
||||
capability chown,
|
||||
capability fsetid,
|
||||
capability sys_module,
|
||||
capability mknod,
|
||||
|
||||
ptrace (read),
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue