Commit graph

50 commits

Author SHA1 Message Date
Alexandre Pujol
053ce04c8e
feat(tunanle): add the sqlhex variable. 2025-05-18 13:09:06 +02:00
Alexandre Pujol
dbd0a7d271
feat(tunable): add the efi variable. 2025-05-17 22:25:58 +02:00
Alexandre Pujol
415c09ca88
feat(tunable): add alias from which.debianutils to which. 2025-05-14 22:43:58 +02:00
Alexandre Pujol
0f8032f9e8
feat(tunable): configure sbin across distributions. 2025-04-28 21:57:26 +02:00
Alexandre Pujol
24b1c816e5
feat(tunable): add @{sbin} variable
Will be used in the future for all programs inside /usr/sbin.
2025-03-14 21:35:50 +01:00
Alexandre Pujol
f270809c5f
feat(tunable): set alias // -> / for all install.
This is required when the re-attached path feature is enabled.
2025-03-06 23:49:55 +01:00
Alexandre Pujol
835b73f64e
build: prepare apparmor 4.1
Split upstreamed and non upstreamed tunable so that it easy to ignore the upstreamed version on apparmor 4.1.
2025-03-01 14:27:55 +01:00
nobody43
078b0de752 Fix rand typo 2025-01-10 23:30:20 +01:00
Alexandre Pujol
23eb08344c
fix(tunable): udbus can be any hex up to 16. 2024-11-21 20:02:16 +00:00
Alexandre Pujol
4e5f4cb06a
feat: profiles and integration tests improvments.
Add the udbus variable to be used in `unix bind` rule for dbus.
2024-11-19 19:04:27 +00:00
Alexandre Pujol
72d45c2cf5
feat(tunable): better definition of the version var. 2024-11-11 20:47:07 +00:00
Alexandre Pujol
604e71888c
feat(tunable): remove never used hci_id. 2024-10-14 20:38:27 +01:00
Alexandre Pujol
0dbc42e357
fix(profile): ensure abi3 compatibility with re-attached path.
See  #559, #558 #557 #555
2024-10-14 15:56:37 +01:00
Alexandre Pujol
61a27bc336
feat(profile): initial integration with attached path.
The feature is not yet enabled.

See https://apparmor.pujol.io/development/internal/#re-attached-path
2024-10-11 14:13:17 +01:00
Alexandre Pujol
28706b2a78
doc: initial preparation for re-attached path. 2024-10-08 22:53:52 +01:00
Alexandre Pujol
18a71512a9
feat(tunable): add u32 & u64.
- Reorganize the file
- @{u32} == @{uid}
2024-10-04 14:42:11 +01:00
Alexandre Pujol
90a8e44d20
feat(tunable): add more system vars. 2024-09-25 13:05:35 +01:00
Alexandre Pujol
156cce5362
feat(profile): restrict dbus in dbus
even dbus-* profiles do not need access to the full bus.
2024-09-25 00:48:42 +01:00
Alexandre Pujol
7f657780e5
feat(tunable): add the word @{w} and digit @{d} variables. 2024-09-21 22:24:45 +01:00
Alexandre Pujol
5474a5fa69
feat(tunable): update the arch variable. 2024-09-13 19:40:17 +01:00
Alexandre Pujol
1807f1dfe5
feat(tunable): add busmae variable for dbus unique name. 2024-09-13 19:39:51 +01:00
Alexandre Pujol
9ea9f1eeed
feat(tunable): add the new @{u8} and @{u16} variable. 2024-09-10 18:55:41 +01:00
Alexandre Pujol
7f594d51b5
feat(tunable): add the new @{arch} variable. 2024-09-10 18:49:33 +01:00
Alexandre Pujol
35dcde9d90
feat(tunable): add the new version variable. 2024-09-05 14:05:35 +01:00
Alexandre Pujol
788d865939
feat(profile): general update. 2024-08-20 20:56:58 +01:00
Alexandre Pujol
93313422bd
feat(profile): update kde profiles on openSUSE Tumbleweed.
See #424
2024-08-20 18:49:52 +01:00
Alexandre Pujol
a270b7c6d4
fix(tunable): username can have uppercase letter.
See #409
2024-07-14 12:13:16 +01:00
REmerald
eb480672f3
fix(abstractions, tunables): move vim modeline
Move vim syntax comment to the end of the file, separated by newline, as requested in #380.
2024-06-15 21:59:31 +01:00
REmerald
1517ff0296
feat(tunables): vim syntax support
Add vim syntax highlighting support introduced in the apparmor package
2024-06-15 21:57:49 +01:00
Alexandre Pujol
c785b41451
feat(profile): general update. 2024-05-18 22:35:05 +01:00
Alexandre Pujol
855f25da9b
feat(tunable): add hex38. 2024-05-14 12:55:57 +01:00
Alexandre Pujol
bed9545082
feat(profile): general update. 2024-05-08 20:08:41 +01:00
Alexandre Pujol
da7747e0fe
feat(tunable): add all int, hex and read variable from 2 to 64. 2024-05-08 18:27:16 +01:00
Alexandre Pujol
66c8f42d94
feat(tunable): add the new @{user} variable 2024-05-07 17:41:34 +01:00
Alexandre Pujol
f607fee8e1
feat(tunable): limit suse multiarch on opensuse. 2024-05-06 19:26:04 +01:00
Alexandre Pujol
88387956de
feat(tunable): add gvfs dir to MOUNTS. 2024-05-06 19:25:31 +01:00
Alexandre Pujol
0ffd70319b
feat(tunable): add @{hex16} 2024-05-05 17:49:45 +01:00
Alexandre Pujol
0bbbe71422
feat(tunable): add the new @{tmp} variable
Mostly used to handle libpam-tmpdir. See #318 #320
2024-05-02 21:42:33 +01:00
Alexandre Pujol
6dd0c36e9a
feat: prefix variables that refer to a profile 2024-04-02 13:41:08 +01:00
Alexandre Pujol
ceb78d971e
feat(tunables): improve hex variables. 2024-03-19 21:15:50 +00:00
Alexandre Pujol
9007daf842
feat(tunable): opensuse has a special multiarch. 2024-03-19 14:49:17 +00:00
Alexandre Pujol
1148b8faad
feat(tunable): improve our variables definition. 2024-03-16 19:42:25 +00:00
Jeroen Rijken
f60234d74a Restore libexec
Signed-off-by: Jeroen Rijken <jeroen.rijken@xs4all.nl>
2024-02-21 13:56:40 +00:00
Jeroen Rijken
062a766e06 Typo
Signed-off-by: Jeroen Rijken <jeroen.rijken@xs4all.nl>
2024-02-21 13:56:40 +00:00
Jeroen Rijken
7addadfa7b Add multiarch to lib
Signed-off-by: Jeroen Rijken <jeroen.rijken@xs4all.nl>
2024-02-21 13:56:40 +00:00
Jeroen Rijken
4c5a21145a General update
Signed-off-by: Jeroen Rijken <jeroen.rijken@xs4all.nl>
2024-02-21 13:56:40 +00:00
Alexandre Pujol
e02bf03cca
feat(tunable): add new system_user variable. 2024-02-14 23:58:18 +00:00
Alexandre Pujol
2cd14aa6bb
chore: add missing and update copyright year. 2024-02-07 00:16:21 +01:00
Alexandre Pujol
e1a30cbf7d
feat(profile): unify udev char dynamic assignment ranges. 2023-12-17 12:46:27 +00:00
Alexandre Pujol
9e402987c6
feat(tunables): add paths tunable
To track common path of some major software.
2023-12-08 17:51:08 +00:00
Renamed from apparmor.d/tunables/multiarch.d/apparmor.d (Browse further)