From f31a68ca216bb33fa8b62648703aad29057b1e0d Mon Sep 17 00:00:00 2001 From: Alexandre Pujol Date: Mon, 9 Sep 2024 19:58:17 +0100 Subject: [PATCH] feat(profile): add gitg. --- apparmor.d/profiles-g-l/gitg | 44 ++++++++++++++++++++++++++++++++++++ 1 file changed, 44 insertions(+) create mode 100644 apparmor.d/profiles-g-l/gitg diff --git a/apparmor.d/profiles-g-l/gitg b/apparmor.d/profiles-g-l/gitg new file mode 100644 index 000000000..3d6da038c --- /dev/null +++ b/apparmor.d/profiles-g-l/gitg @@ -0,0 +1,44 @@ +# apparmor.d - Full set of apparmor profiles +# Copyright (C) 2024 Alexandre Pujol +# SPDX-License-Identifier: GPL-2.0-only + +abi , + +include + +@{exec_path} = @{bin}/gitg +profile gitg @{exec_path} { + include + include + include + include + include + include + include + + network inet dgram, + network inet6 dgram, + network inet stream, + network inet6 stream, + network netlink raw, + + @{exec_path} mr, + + /usr/share/gitg/{,**} r, + + owner @{user_projects_dirs}/ rw, + owner @{user_projects_dirs}/** rwkl -> @{user_projects_dirs}/**, + owner @{user_projects_dirs}/**/.git/hooks/* rix, + + owner @{user_config_dirs}/git/{,*} rw, + + owner @{user_share_dirs}/gitg/{,**} rw, + + @{run}/mount/utab r, + + owner @{PROC}/@{pid}/mountinfo r, + + include if exists +} + +# vim:syntax=apparmor