fix(profile): add deny-sensitive-home abstraction.

This commit is contained in:
Alexandre Pujol 2022-10-01 19:18:54 +01:00
parent 8a55eb8330
commit d0a8030af8
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
3 changed files with 38 additions and 0 deletions

View file

@ -58,6 +58,7 @@ profile nautilus @{exec_path} flags=(attach_disconnected) {
owner /tmp/{,**} rw,
# Silence non user's data
include <abstractions/deny-sensitive-home>
deny /boot/{,**} r,
deny /opt/{,**} r,
deny /root/{,**} r,

View file

@ -12,6 +12,7 @@ profile tracker-miner @{exec_path} {
include <abstractions/dbus-session-strict>
include <abstractions/dbus-strict>
include <abstractions/dconf-write>
include <abstractions/deny-sensitive-home>
include <abstractions/disks-read>
include <abstractions/freedesktop.org>
include <abstractions/nameservice-strict>