apparmor.d/apparmor.d/profiles-a-f/fwupd

111 lines
2.7 KiB
Text
Raw Normal View History

# apparmor.d - Full set of apparmor profiles
2022-03-04 22:30:34 +01:00
# Copyright (C) 2020-2022 Mikhail Morfikov
# Copyright (C) 2021-2022 Alexandre Pujol <alexandre@pujol.io>
# SPDX-License-Identifier: GPL-2.0-only
2020-12-10 22:33:39 +01:00
abi <abi/3.0>,
2020-12-10 22:33:39 +01:00
include <tunables/global>
@{exec_path} = /{usr/,}bin/fwupd /{usr/,}lib/fwupd/fwupd
profile fwupd @{exec_path} flags=(complain,attach_disconnected) {
2020-12-10 22:33:39 +01:00
include <abstractions/base>
2021-08-14 13:59:24 +02:00
include <abstractions/disks-read>
2020-12-10 22:33:39 +01:00
include <abstractions/nameservice-strict>
2021-08-14 13:59:24 +02:00
include <abstractions/openssl>
capability dac_override,
2021-08-14 13:59:24 +02:00
capability dac_read_search,
capability linux_immutable,
capability mknod,
capability sys_admin,
capability sys_nice,
capability sys_rawio,
capability syslog,
2021-08-14 13:59:24 +02:00
network netlink raw,
@{exec_path} mr,
/{usr/,}bin/gpg rCx -> gpg,
/{usr/,}bin/gpgconf rCx -> gpg,
/{usr/,}bin/gpgsm rCx -> gpg,
2021-10-22 16:01:43 +02:00
/etc/pki/fwupd/{,**} r,
/etc/pki/fwupd-metadata/{,**} r,
/etc/fwupd/{,**} r,
/usr/share/fwupd/{,**} r,
2021-08-14 13:59:24 +02:00
2021-10-22 16:01:43 +02:00
/var/cache/fwupd/{,**} rw,
2021-08-14 13:59:24 +02:00
/var/lib/fwupd/{,**} rw,
/var/lib/fwupd/pending.db rwk,
/boot/{,**} r,
/boot/EFI/arch/fwupdx[0-9]*.efi rw,
/boot/EFI/arch/fw/fwupd-*.cap{,.*} rw,
/usr/share/mime/mime.cache r,
2022-03-04 22:30:34 +01:00
/etc/machine-id r,
/var/lib/dbus/machine-id r,
2022-03-04 22:30:34 +01:00
# In order to get to this file, the attach_disconnected flag has to be set
owner @{user_cache_dirs}/fwupd/lvfs-metadata.xml.gz r,
@{sys}/**/ r,
@{sys}/devices/** r,
2021-08-14 13:59:24 +02:00
@{sys}/firmware/acpi/** r,
@{sys}/firmware/dmi/tables/DMI r,
2021-08-14 13:59:24 +02:00
@{sys}/firmware/dmi/tables/smbios_entry_point r,
@{sys}/firmware/efi/** r,
@{sys}/firmware/efi/efivars/BootNext-* rw,
2021-10-07 15:50:46 +02:00
@{sys}/firmware/efi/efivars/fwupd-* rw,
@{sys}/kernel/security/lockdown r,
2021-08-14 13:59:24 +02:00
@{sys}/kernel/security/tpm[0-9]/binary_bios_measurements r,
@{sys}/power/mem_sleep r,
2022-03-04 22:30:34 +01:00
@{run}/motd.d/ r,
@{run}/motd.d/[0-9]*-fwupd* rw,
2022-01-18 00:45:11 +01:00
@{run}/motd.d/fwupd/{,**} rw,
2022-03-04 22:30:34 +01:00
@{run}/mount/utab r,
2021-08-14 13:59:24 +02:00
@{run}/systemd/inhibit/[0-9]*.ref rw,
2022-03-04 22:30:34 +01:00
@{run}/udev/data/* r,
2022-03-04 22:30:34 +01:00
@{PROC}/@{pids}/fd/ r,
@{PROC}/@{pids}/mountinfo r,
@{PROC}/@{pids}/mounts r,
@{PROC}/1/cgroup r,
@{PROC}/cmdline r,
@{PROC}/modules r,
@{PROC}/swaps r,
@{PROC}/sys/kernel/tainted r,
/dev/bus/usb/ r,
/dev/bus/usb/[0-9]*/[0-9]* rw,
/dev/drm_dp_aux[0-9]* rw,
/dev/mei[0-9]* rw,
/dev/mem r,
/dev/sd[a-z]* r,
/dev/tpm[0-9]* rw,
/dev/wmi/* r,
2021-08-14 13:59:24 +02:00
profile gpg flags=(complain) {
2020-12-10 22:33:39 +01:00
include <abstractions/base>
2021-08-14 13:59:24 +02:00
include <abstractions/nameservice-strict>
2021-10-07 15:50:46 +02:00
capability dac_read_search,
/{usr/,}bin/gpg mr,
/{usr/,}bin/gpgconf mr,
/{usr/,}bin/gpgsm mr,
2021-08-14 13:59:24 +02:00
/{usr/,}bin/gpg-agent mr,
owner /var/lib/fwupd/gnupg/ rw,
owner /var/lib/fwupd/gnupg/** rwkl -> /var/lib/fwupd/gnupg/**,
}
2020-12-10 22:33:39 +01:00
include if exists <local/fwupd>
}