Update various profiles

Signed-off-by: Jeroen Rijken <jeroen.rijken@xs4all.nl>
This commit is contained in:
Jeroen Rijken 2024-02-21 23:52:26 +01:00 committed by Alex
parent 92a1d9f65f
commit b532dd6827
47 changed files with 459 additions and 26 deletions

View file

@ -18,6 +18,8 @@ profile brave @{exec_path} {
include <abstractions/base>
include <abstractions/chromium>
unix (send, receive) type=stream peer=brave-crashpad-handler,
@{exec_path} mrix,
@{bin}/man rPUx, # For "brave --help"
@ -25,8 +27,10 @@ profile brave @{exec_path} {
/usr/share/chromium/extensions/ r,
/etc/opt/chrome/ r,
/etc/opt/chrome/native-messaging-hosts/* r,
owner @{user_config_dirs}/BraveSoftware/ rw,
owner @{user_config_dirs}/kioslaverc r,
owner @{user_config_dirs}/menus/applications-merged/ r,
owner @{user_config_dirs}/menus/applications-merged/xdg-desktop-menu-dummy.menu r,
@ -42,6 +46,7 @@ profile brave @{exec_path} {
# Silencer
deny /etc/opt/chrome/ w,
deny /dev/disk/by-uuid/ r,
include if exists <local/brave>
}

View file

@ -16,11 +16,15 @@ profile brave-crashpad-handler @{exec_path} {
capability sys_ptrace,
unix (send, receive) type=stream peer=(label=brave),
ptrace peer=brave,
signal (send) peer=brave,
@{exec_path} mrix,
owner @{user_config_dirs}/BraveSoftware/Brave-Browser/CrashpadMetrics-active.pma rw,
owner @{user_config_dirs}/BraveSoftware/Brave-Browser/CrashpadMetrics.pma rw,
owner "@{config_dirs}/Crash Reports/**" rwk,
@{PROC}/sys/kernel/yama/ptrace_scope r,

View file

@ -27,7 +27,7 @@ profile brave-wrapper @{exec_path} {
@{lib_dirs}/brave rPx,
owner @{PROC}/@{pid}/fd/ w,
owner @{PROC}/@{pid}/fd/@{int} w,
# Silencer
deny @{user_share_dirs}/gvfs-metadata/* r,