chore: various cosmetic changes.

This commit is contained in:
Alexandre Pujol 2023-09-01 19:26:52 +01:00
parent 256d4abde8
commit aea0034fcc
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
16 changed files with 35 additions and 32 deletions

View file

@ -3,10 +3,11 @@
# Copyright (C) 2021-2022 Alexandre Pujol <alexandre@pujol.io>
# SPDX-License-Identifier: GPL-2.0-only
abi <abi/3.0>,
ptrace (read),
@{sys}/firmware/efi/efivars/SecureBoot-@{uuid} r,
@{sys}/fs/cgroup/system.slice/@{profile_name}.service/memory.pressure rw,
@{PROC}/1/cgroup r,
@{PROC}/1/environ r,
@{PROC}/1/sched r,
@ -17,7 +18,4 @@
/dev/kmsg w,
@{sys}/firmware/efi/efivars/SecureBoot-@{uuid} r,
@{sys}/fs/cgroup/system.slice/@{profile_name}.service/memory.pressure rw,
include if exists <abstractions/systemd-common.d>

View file

@ -2,7 +2,7 @@
# Copyright (C) 2023 Alexandre Pujol <alexandre@pujol.io>
# SPDX-License-Identifier: GPL-2.0-only
owner @{run}/user/@{uid}/wayland-@{int}.lock rk,
owner /dev/shm/sway* rw,
owner /dev/shm/dunst-@{rand6} rw,
owner @{run}/user/@{uid}/wayland-@{int}.lock rk,

View file

@ -20,6 +20,7 @@ profile avahi-autoipd @{exec_path} {
signal receive set=(kill,term),
@{exec_path} mr,
/etc/avahi/avahi-autoipd.action rix,
include if exists <local/avahi-autoipd>

View file

@ -57,7 +57,7 @@ profile grub-mkconfig @{exec_path} {
@{bin}/umount rPx,
@{bin}/uname rix,
@{bin}/which{.debianutils,} rix,
/etc/grub.d/{**,} rix,
/etc/grub.d/{**,} rix,
/boot/{**,} r,
/boot/grub/{**,} rw,

View file

@ -18,13 +18,13 @@ profile grub-probe @{exec_path} {
@{exec_path} mr,
/{usr/,}{local/,}{s,}bin/zpool rPx,
@{bin}/lvm rPx,
@{bin}/lsb_release rPx -> lsb_release,
@{bin}/lvm rPx,
@{bin}/udevadm rPx,
/ r,
/usr/share/grub/* r,
/ r,
/boot/ r,
/boot/grub/themes/{,**} r,

View file

@ -56,6 +56,7 @@ profile k3s @{exec_path} flags=(attach_disconnected) {
unix (bind,listen) type=stream addr=@xtables,
@{exec_path} mr,
@{bin}/kmod rPx,
@{bin}/mount rPx,
@{bin}/systemd-run rix,

View file

@ -12,7 +12,8 @@ profile syncoid @{exec_path} flags=(complain) {
include <abstractions/consoles>
include <abstractions/perl>
@{exec_path} mr,
@{exec_path} mr,
@{bin}/{,ba,da}sh rix,
@{bin}/grep rix,
@{bin}/mbuffer rix,