* Unbreaking Debian 11 and partially Ubuntu 22.04 * pre-cleanup * pre-cleanup2 * Update im-launch * Update gnome-extension-ding * polishing * not yet * Update ubuntu.flags Allow GDM to boot. `No new privs` fix. * Update debian.flags Allow GDM to boot. `No new privs` fix. * Update CONTRIBUTING.md * fixes * reverting w * move setpriv to main.flags
174 lines
5.8 KiB
Text
174 lines
5.8 KiB
Text
# apparmor.d - Full set of apparmor profiles
|
|
# Copyright (C) 2022 Alexandre Pujol <alexandre@pujol.io>
|
|
# SPDX-License-Identifier: GPL-2.0-only
|
|
|
|
abi <abi/3.0>,
|
|
|
|
include <tunables/global>
|
|
|
|
@{exec_path} = /usr/share/gnome-shell/extensions/ding@rastersoft.com/ding.js
|
|
profile gnome-extension-ding @{exec_path} {
|
|
include <abstractions/base>
|
|
include <abstractions/nameservice-strict>
|
|
include <abstractions/dbus-strict>
|
|
include <abstractions/dbus-session-strict>
|
|
include <abstractions/dbus-accessibility-strict>
|
|
include <abstractions/dconf-write>
|
|
include <abstractions/fonts>
|
|
include <abstractions/freedesktop.org>
|
|
include <abstractions/gtk>
|
|
|
|
unix (send,receive) type=stream addr=none peer=(label=gnome-shell),
|
|
|
|
dbus send bus=session path=/org/freedesktop/DBus
|
|
interface=org.freedesktop.DBus
|
|
member={RequestName,ReleaseName}
|
|
peer=(name=org.freedesktop.DBus, label=dbus-daemon),
|
|
|
|
dbus send bus=system path=/org/freedesktop/DBus
|
|
interface=org.freedesktop.DBus
|
|
member={ListNames,ListActivatableNames},
|
|
|
|
dbus send bus=session path=/org/freedesktop/DBus
|
|
interface=org.freedesktop.DBus
|
|
member={RequestName,ReleaseName,ListNames,ListActivatableNames}
|
|
peer=(name=org.freedesktop.DBus, label=dbus-daemon),
|
|
|
|
dbus send bus=system path=/org/freedesktop/DBus
|
|
interface=org.freedesktop.DBus.Properties
|
|
member=GetAll
|
|
peer=(name=org.freedesktop.DBus, label=dbus-daemon),
|
|
|
|
dbus send bus=session path=/org/freedesktop/DBus
|
|
interface=org.freedesktop.DBus.Properties
|
|
member=GetAll
|
|
peer=(name=org.freedesktop.DBus, label=dbus-daemon),
|
|
|
|
dbus send bus=system path=/org/freedesktop/DBus
|
|
interface=org.freedesktop.DBus.Introspectable
|
|
member=Introspect,
|
|
|
|
dbus send bus=system path=/net/hadess/SwitcherooControl
|
|
interface=org.freedesktop.DBus.Properties
|
|
member=GetAll,
|
|
|
|
dbus send bus=session path=/org/freedesktop/Notifications
|
|
interface=org.freedesktop.DBus.Properties
|
|
member=GetAll
|
|
peer=(name=:*, label=gjs-console),
|
|
|
|
dbus send bus=session path=/org/gtk/vfs/metadata
|
|
interface=org.freedesktop.DBus.Properties
|
|
member=GetAll
|
|
peer=(name=:*, label=gvfsd-metadata),
|
|
|
|
dbus send bus=session path=/org/gtk/vfs/Daemon
|
|
interface=org.gtk.vfs.Daemon
|
|
member=ListMonitorImplementations
|
|
peer=(name=:*, label=gvfsd),
|
|
|
|
dbus receive bus=session path=/org/gnome/SessionManager
|
|
interface=org.gnome.SessionManager
|
|
member=ClientRemoved
|
|
peer=(name=:*, label=gnome-session-binary),
|
|
|
|
dbus send bus=session path=/org/gtk/Private/RemoteVolumeMonitor
|
|
interface=org.gtk.Private.RemoteVolumeMonitor
|
|
member={IsSupported,List}
|
|
peer=(name=:*, label=gvfs-*-monitor),
|
|
|
|
dbus send bus=session path=/org/gtk/vfs/mounttracker
|
|
interface=org.gtk.vfs.MountTracker
|
|
member={ListMounts2,ListMountableInfo}
|
|
peer=(name=:*, label=gvfsd),
|
|
|
|
dbus receive bus=session path=/org/gtk/vfs/mounttracker
|
|
interface=org.gtk.vfs.MountTracker
|
|
member=Mounted
|
|
peer=(name=:*, label=gvfsd),
|
|
|
|
dbus send bus=session path=/org/gtk/Settings
|
|
interface=org.freedesktop.DBus.Properties
|
|
member=GetAll
|
|
peer=(name=:*, label=gsd-xsettings),
|
|
|
|
dbus send bus=accessibility path=/org/a11y/atspi/registry
|
|
interface=org.a11y.atspi.Registry
|
|
member=GetRegisteredEvents
|
|
peer=(name=org.a11y.atspi.Registry), # all peer's labels
|
|
|
|
dbus receive bus=accessibility path=/org/a11y/atspi/registry
|
|
interface=org.a11y.atspi.Registry
|
|
member=EventListenerDeregistered
|
|
peer=(name=:*, label=at-spi2-registryd),
|
|
|
|
dbus send bus=accessibility path=/org/a11y/atspi/registry/deviceeventcontroller
|
|
interface=org.a11y.atspi.DeviceEventController
|
|
member={GetKeystrokeListeners,GetDeviceEventListeners}
|
|
peer=(name=org.a11y.atspi.Registry), # all peer's labels
|
|
|
|
dbus send bus=accessibility path=/org/a11y/atspi/accessible/root
|
|
interface=org.a11y.atspi.Socket
|
|
member=Embed
|
|
peer=(name=org.a11y.atspi.Registry), # all peer's labels
|
|
|
|
dbus send bus=session path=/org/a11y/bus
|
|
interface=org.a11y.Bus
|
|
member=GetAddress
|
|
peer=(name=org.a11y.Bus, label=at-spi-bus-launcher),
|
|
|
|
dbus receive bus=accessibility path=/org/a11y/atspi/accessible/root
|
|
interface=org.freedesktop.DBus.Properties
|
|
member=Set
|
|
peer=(name=:*, label=at-spi2-registryd),
|
|
|
|
dbus send bus=session path=/com/rastersoft/dingextension/control
|
|
interface=org.gtk.Actions
|
|
member=DescribeAll
|
|
peer=(name=com.rastersoft.dingextension, label=gnome-shell),
|
|
|
|
dbus receive bus=session path=/com/rastersoft/ding
|
|
interface=org.gtk.Actions
|
|
member=DescribeAll
|
|
peer=(name=:*, label=gnome-shell),
|
|
|
|
dbus receive bus=session path=/com/rastersoft/ding
|
|
interface=org.freedesktop.DBus.Properties
|
|
member=GetAll
|
|
peer=(name=:*, label=gnome-shell),
|
|
|
|
dbus bind bus=session
|
|
name=com.rastersoft.ding,
|
|
|
|
@{exec_path} mr,
|
|
|
|
/{usr/,}bin/{,ba,da}sh rix,
|
|
/{usr/,}bin/env rix,
|
|
/{usr/,}bin/gjs-console rix,
|
|
/{usr/,}bin/gnome-control-center rPx,
|
|
/{usr/,}bin/nautilus rPx,
|
|
|
|
/usr/share/glib-2.0/schemas/gschemas.compiled r,
|
|
/usr/share/gnome-shell/extensions/ding@rastersoft.com/* r,
|
|
/usr/share/thumbnailers/{,*.thumbnailer} r,
|
|
/usr/share/ubuntu/applications/{,**} r,
|
|
/usr/share/X11/{,**} r,
|
|
|
|
/etc/gnome/defaults.list r,
|
|
|
|
/var/lib/snapd/desktop/icons/{,**} r,
|
|
|
|
owner @{HOME}/@{XDG_TEMPLATES_DIR}/ r,
|
|
owner @{HOME}/@{XDG_DESKTOP_DIR}/ r,
|
|
|
|
owner @{user_share_dirs}/nautilus/scripts/ r,
|
|
|
|
owner @{PROC}/@{pid}/mountinfo r,
|
|
owner @{PROC}/@{pid}/mounts r,
|
|
owner @{PROC}/@{pid}/stat r,
|
|
owner @{PROC}/@{pid}/task/@{tid}/stat r,
|
|
|
|
deny owner @{user_share_dirs}/gvfs-metadata/{,*} r,
|
|
|
|
include if exists <local/gnome-extension-ding>
|
|
}
|