feat(profiles): general update.
This commit is contained in:
parent
d0a8030af8
commit
ac47e292ac
15 changed files with 44 additions and 37 deletions
|
|
@ -13,6 +13,10 @@
|
||||||
/usr/local/bin/ r,
|
/usr/local/bin/ r,
|
||||||
/usr/local/bin/[a-zA-Z0-9]* rPUx,
|
/usr/local/bin/[a-zA-Z0-9]* rPUx,
|
||||||
|
|
||||||
|
# All apps in opt
|
||||||
|
/opt/*/ r,
|
||||||
|
/opt/*/[a-zA-Z0-9]* rPUx,
|
||||||
|
|
||||||
# Firefox
|
# Firefox
|
||||||
/{usr/,}lib/ r,
|
/{usr/,}lib/ r,
|
||||||
/{usr/,}lib/firefox/ r,
|
/{usr/,}lib/firefox/ r,
|
||||||
|
|
@ -34,10 +38,4 @@
|
||||||
/usr/share/discord/ r,
|
/usr/share/discord/ r,
|
||||||
/usr/share/discord/Discord rPx,
|
/usr/share/discord/Discord rPx,
|
||||||
|
|
||||||
# FreeTube
|
|
||||||
/opt/FreeTube/ r,
|
|
||||||
/opt/FreeTube/freetube rPx,
|
|
||||||
/opt/FreeTube-Vue/ r,
|
|
||||||
/opt/FreeTube-Vue/freetube-vue rPx,
|
|
||||||
|
|
||||||
include if exists <abstractions/app-launcher-user.d>
|
include if exists <abstractions/app-launcher-user.d>
|
||||||
|
|
@ -1,5 +1,6 @@
|
||||||
# apparmor.d - Full set of apparmor profiles
|
# apparmor.d - Full set of apparmor profiles
|
||||||
# Copyright (C) 2018-2021 Mikhail Morfikov
|
# Copyright (C) 2018-2021 Mikhail Morfikov
|
||||||
|
# Copyright (C) 2021-2022 Alexandre Pujol <alexandre@pujol.io>
|
||||||
# SPDX-License-Identifier: GPL-2.0-only
|
# SPDX-License-Identifier: GPL-2.0-only
|
||||||
|
|
||||||
abi <abi/3.0>,
|
abi <abi/3.0>,
|
||||||
|
|
@ -9,8 +10,8 @@ include <tunables/global>
|
||||||
@{exec_path} = /{usr/,}bin/xdg-open
|
@{exec_path} = /{usr/,}bin/xdg-open
|
||||||
profile xdg-open @{exec_path} flags=(attach_disconnected) {
|
profile xdg-open @{exec_path} flags=(attach_disconnected) {
|
||||||
include <abstractions/base>
|
include <abstractions/base>
|
||||||
include <abstractions/consoles>
|
|
||||||
include <abstractions/app-launcher-user>
|
include <abstractions/app-launcher-user>
|
||||||
|
include <abstractions/consoles>
|
||||||
|
|
||||||
@{exec_path} r,
|
@{exec_path} r,
|
||||||
|
|
||||||
|
|
@ -29,27 +30,16 @@ profile xdg-open @{exec_path} flags=(attach_disconnected) {
|
||||||
/{usr/,}bin/gio rPx,
|
/{usr/,}bin/gio rPx,
|
||||||
#/{usr/,}bin/kde-open5 rPUx,
|
#/{usr/,}bin/kde-open5 rPUx,
|
||||||
|
|
||||||
# When xdg-open is run as root, it wants to exec dbus-launch, and hence it creates the two
|
/{usr/,}bin/dbus-launch rCx -> dbus,
|
||||||
# following root processes:
|
/{usr/,}bin/dbus-send rCx -> dbus,
|
||||||
# dbus-launch --autolaunch e0a30ad97cd6421c85247839ccef9db2 --binary-syntax --close-stderr
|
|
||||||
# /usr/bin/dbus-daemon --syslog-only --fork --print-pid 5 --print-address 7 --session
|
|
||||||
#
|
|
||||||
# Should this be allowed? Xdg-open works fine without this.
|
|
||||||
#/{usr/,}bin/dbus-launch rCx -> dbus,
|
|
||||||
#/{usr/,}bin/dbus-send rCx -> dbus,
|
|
||||||
deny /{usr/,}bin/dbus-launch rx,
|
|
||||||
deny /{usr/,}bin/dbus-send rx,
|
|
||||||
|
|
||||||
/usr/share/applications/*.desktop r,
|
/usr/share/applications/*.desktop r,
|
||||||
owner @{user_share_dirs}/applications/ r,
|
|
||||||
|
|
||||||
owner @{HOME}/.Xauthority r,
|
|
||||||
|
|
||||||
/** r,
|
/** r,
|
||||||
owner /** rw,
|
owner /** rw,
|
||||||
|
|
||||||
# file_inherit
|
owner @{user_share_dirs}/applications/ r,
|
||||||
/dev/dri/card[0-9]* rw,
|
|
||||||
/dev/tty rw,
|
/dev/tty rw,
|
||||||
|
|
||||||
profile dbus {
|
profile dbus {
|
||||||
|
|
|
||||||
|
|
@ -9,6 +9,7 @@ include <tunables/global>
|
||||||
|
|
||||||
@{exec_path} = /{usr/,}bin/gio
|
@{exec_path} = /{usr/,}bin/gio
|
||||||
@{exec_path} += /{usr/,}bin/gio-launch-desktop
|
@{exec_path} += /{usr/,}bin/gio-launch-desktop
|
||||||
|
@{exec_path} += /{usr/,}lib/gio-launch-desktop
|
||||||
@{exec_path} += /{usr/,}lib/@{multiarch}/glib-[0-9]*/gio-launch-desktop
|
@{exec_path} += /{usr/,}lib/@{multiarch}/glib-[0-9]*/gio-launch-desktop
|
||||||
profile gio-launch-desktop @{exec_path} flags=(attach_disconnected) {
|
profile gio-launch-desktop @{exec_path} flags=(attach_disconnected) {
|
||||||
include <abstractions/base>
|
include <abstractions/base>
|
||||||
|
|
|
||||||
|
|
@ -15,6 +15,9 @@ profile gnome-music @{exec_path} {
|
||||||
include <abstractions/gstreamer>
|
include <abstractions/gstreamer>
|
||||||
include <abstractions/mesa>
|
include <abstractions/mesa>
|
||||||
include <abstractions/nameservice-strict>
|
include <abstractions/nameservice-strict>
|
||||||
|
include <abstractions/opencl-intel>
|
||||||
|
include <abstractions/opencl-mesa>
|
||||||
|
include <abstractions/opencl-nvidia>
|
||||||
include <abstractions/openssl>
|
include <abstractions/openssl>
|
||||||
include <abstractions/p11-kit>
|
include <abstractions/p11-kit>
|
||||||
include <abstractions/python>
|
include <abstractions/python>
|
||||||
|
|
|
||||||
|
|
@ -9,7 +9,6 @@ include <tunables/global>
|
||||||
@{exec_path} = /{usr/,}bin/nautilus
|
@{exec_path} = /{usr/,}bin/nautilus
|
||||||
profile nautilus @{exec_path} flags=(attach_disconnected) {
|
profile nautilus @{exec_path} flags=(attach_disconnected) {
|
||||||
include <abstractions/base>
|
include <abstractions/base>
|
||||||
include <abstractions/app-launcher-user>
|
|
||||||
include <abstractions/dbus-session-strict>
|
include <abstractions/dbus-session-strict>
|
||||||
include <abstractions/dbus-strict>
|
include <abstractions/dbus-strict>
|
||||||
include <abstractions/dconf-write>
|
include <abstractions/dconf-write>
|
||||||
|
|
|
||||||
|
|
@ -20,7 +20,9 @@ profile bootctl @{exec_path} {
|
||||||
|
|
||||||
@{exec_path} mr,
|
@{exec_path} mr,
|
||||||
|
|
||||||
/{usr/,}bin/less rPx -> child-pager,
|
/{usr/,}bin/less rPx -> child-pager,
|
||||||
|
/{usr/,}bin/more rPx -> child-pager,
|
||||||
|
/{usr/,}bin/pager rPx -> child-pager,
|
||||||
|
|
||||||
/{boot,efi}/ r,
|
/{boot,efi}/ r,
|
||||||
/{boot,efi}/EFI/{,**} r,
|
/{boot,efi}/EFI/{,**} r,
|
||||||
|
|
|
||||||
|
|
@ -9,8 +9,19 @@ include <tunables/global>
|
||||||
@{exec_path} = /{usr/,}bin/busctl
|
@{exec_path} = /{usr/,}bin/busctl
|
||||||
profile busctl @{exec_path} {
|
profile busctl @{exec_path} {
|
||||||
include <abstractions/base>
|
include <abstractions/base>
|
||||||
|
include <abstractions/nameservice-strict>
|
||||||
|
|
||||||
|
ptrace (read),
|
||||||
|
|
||||||
@{exec_path} mr,
|
@{exec_path} mr,
|
||||||
|
|
||||||
|
/{usr/,}bin/less rPx -> child-pager,
|
||||||
|
/{usr/,}bin/more rPx -> child-pager,
|
||||||
|
/{usr/,}bin/pager rPx -> child-pager,
|
||||||
|
|
||||||
|
@{PROC}/@{pids}/cgroup r,
|
||||||
|
@{PROC}/@{pids}/comm r,
|
||||||
|
@{PROC}/@{pids}/stat r,
|
||||||
|
|
||||||
include if exists <local/busctl>
|
include if exists <local/busctl>
|
||||||
}
|
}
|
||||||
|
|
@ -17,9 +17,9 @@ profile coredumpctl @{exec_path} flags=(complain) {
|
||||||
|
|
||||||
/{usr/,}bin/gdb rCx -> gdb,
|
/{usr/,}bin/gdb rCx -> gdb,
|
||||||
|
|
||||||
/{usr/,}bin/pager rPx -> child-pager,
|
|
||||||
/{usr/,}bin/less rPx -> child-pager,
|
/{usr/,}bin/less rPx -> child-pager,
|
||||||
/{usr/,}bin/more rPx -> child-pager,
|
/{usr/,}bin/more rPx -> child-pager,
|
||||||
|
/{usr/,}bin/pager rPx -> child-pager,
|
||||||
|
|
||||||
owner /tmp/*.coredump w,
|
owner /tmp/*.coredump w,
|
||||||
owner /tmp/core.* w,
|
owner /tmp/core.* w,
|
||||||
|
|
|
||||||
|
|
@ -23,9 +23,9 @@ profile journalctl @{exec_path} {
|
||||||
|
|
||||||
@{exec_path} mr,
|
@{exec_path} mr,
|
||||||
|
|
||||||
/{usr/,}bin/pager rPx -> child-pager,
|
|
||||||
/{usr/,}bin/less rPx -> child-pager,
|
/{usr/,}bin/less rPx -> child-pager,
|
||||||
/{usr/,}bin/more rPx -> child-pager,
|
/{usr/,}bin/more rPx -> child-pager,
|
||||||
|
/{usr/,}bin/pager rPx -> child-pager,
|
||||||
|
|
||||||
/var/lib/dbus/machine-id r,
|
/var/lib/dbus/machine-id r,
|
||||||
/etc/machine-id r,
|
/etc/machine-id r,
|
||||||
|
|
|
||||||
|
|
@ -13,9 +13,9 @@ profile localectl @{exec_path} {
|
||||||
|
|
||||||
@{exec_path} mr,
|
@{exec_path} mr,
|
||||||
|
|
||||||
/{usr/,}bin/pager rPx -> child-pager,
|
|
||||||
/{usr/,}bin/less rPx -> child-pager,
|
/{usr/,}bin/less rPx -> child-pager,
|
||||||
/{usr/,}bin/more rPx -> child-pager,
|
/{usr/,}bin/more rPx -> child-pager,
|
||||||
|
/{usr/,}bin/pager rPx -> child-pager,
|
||||||
|
|
||||||
/usr/share/kbd/keymaps/{,**} r,
|
/usr/share/kbd/keymaps/{,**} r,
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -31,9 +31,9 @@ profile networkctl @{exec_path} flags=(attach_disconnected,complain) {
|
||||||
|
|
||||||
@{exec_path} mr,
|
@{exec_path} mr,
|
||||||
|
|
||||||
/{usr/,}bin/pager rPx -> child-pager,
|
/{usr/,}bin/less rPx -> child-pager,
|
||||||
/{usr/,}bin/less rPx -> child-pager,
|
/{usr/,}bin/more rPx -> child-pager,
|
||||||
/{usr/,}bin/more rPx -> child-pager,
|
/{usr/,}bin/pager rPx -> child-pager,
|
||||||
|
|
||||||
/etc/udev/hwdb.bin r,
|
/etc/udev/hwdb.bin r,
|
||||||
/var/lib/dbus/machine-id r,
|
/var/lib/dbus/machine-id r,
|
||||||
|
|
|
||||||
|
|
@ -14,9 +14,9 @@ profile systemd-cgls @{exec_path} {
|
||||||
|
|
||||||
@{exec_path} mr,
|
@{exec_path} mr,
|
||||||
|
|
||||||
/{usr/,}bin/pager rPx -> child-pager,
|
/{usr/,}bin/less rPx -> child-pager,
|
||||||
/{usr/,}bin/less rPx -> child-pager,
|
/{usr/,}bin/more rPx -> child-pager,
|
||||||
/{usr/,}bin/more rPx -> child-pager,
|
/{usr/,}bin/pager rPx -> child-pager,
|
||||||
|
|
||||||
@{sys}/fs/cgroup/{,**} r,
|
@{sys}/fs/cgroup/{,**} r,
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -12,9 +12,9 @@ profile systemd-cgtop @{exec_path} {
|
||||||
|
|
||||||
@{exec_path} mr,
|
@{exec_path} mr,
|
||||||
|
|
||||||
/{usr/,}bin/pager rPx -> child-pager,
|
/{usr/,}bin/less rPx -> child-pager,
|
||||||
/{usr/,}bin/less rPx -> child-pager,
|
/{usr/,}bin/more rPx -> child-pager,
|
||||||
/{usr/,}bin/more rPx -> child-pager,
|
/{usr/,}bin/pager rPx -> child-pager,
|
||||||
|
|
||||||
@{sys}/fs/cgroup/{,**} r,
|
@{sys}/fs/cgroup/{,**} r,
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -14,9 +14,9 @@ profile systemd-mount @{exec_path} {
|
||||||
|
|
||||||
@{exec_path} mr,
|
@{exec_path} mr,
|
||||||
|
|
||||||
/{usr/,}bin/pager rPx -> child-pager,
|
|
||||||
/{usr/,}bin/less rPx -> child-pager,
|
/{usr/,}bin/less rPx -> child-pager,
|
||||||
/{usr/,}bin/more rPx -> child-pager,
|
/{usr/,}bin/more rPx -> child-pager,
|
||||||
|
/{usr/,}bin/pager rPx -> child-pager,
|
||||||
|
|
||||||
@{sys}/bus/ r,
|
@{sys}/bus/ r,
|
||||||
@{sys}/class/ r,
|
@{sys}/class/ r,
|
||||||
|
|
|
||||||
|
|
@ -38,6 +38,9 @@ profile pkttyagent @{exec_path} {
|
||||||
|
|
||||||
@{exec_path} mr,
|
@{exec_path} mr,
|
||||||
|
|
||||||
|
@{libexec}/polkit-agent-helper-[0-9] rPx,
|
||||||
|
/{usr/,}lib/polkit-[0-9]/polkit-agent-helper-[0-9] rPx,
|
||||||
|
|
||||||
owner @{PROC}/@{pids}/stat r,
|
owner @{PROC}/@{pids}/stat r,
|
||||||
|
|
||||||
/dev/tty rw,
|
/dev/tty rw,
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue