mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2025-02-20 08:55:34 +01:00
Add include if exists abstractions *.d
This commit is contained in:
parent
8d22bc10b2
commit
3734e5aedf
28 changed files with 53 additions and 0 deletions
|
@ -9,3 +9,5 @@
|
|||
/usr/ r,
|
||||
/{usr/,}{s,}bin/ r,
|
||||
/{usr/,}{s,}bin/[a-z0-9]* rPUx,
|
||||
|
||||
include if exists <abstractions/app-launcher-root.d>
|
|
@ -36,3 +36,5 @@
|
|||
/opt/FreeTube/freetube rPx,
|
||||
/opt/FreeTube-Vue/ r,
|
||||
/opt/FreeTube-Vue/freetube-vue rPx,
|
||||
|
||||
include if exists <abstractions/app-launcher-user.d>
|
|
@ -26,3 +26,5 @@
|
|||
|
||||
owner /tmp/clearsigned.message.* rw,
|
||||
owner /tmp/#[0-9]*[0-9] rw,
|
||||
|
||||
include if exists <abstractions/apt-common.d>
|
|
@ -19,3 +19,5 @@
|
|||
deny owner @{user_config_dirs}/glib-2.0/settings/ rw,
|
||||
deny owner @{user_config_dirs}/glib-2.0/settings/keyfile rw,
|
||||
deny owner @{user_config_dirs}/glib-2.0/settings/.goutputstream-* rw,
|
||||
|
||||
include if exists <abstractions/deny-dconf.d>
|
|
@ -14,3 +14,5 @@
|
|||
|
||||
# Use audit for now to see whether some apps are trying to get access to the /root/ dir.
|
||||
audit deny /root/{,**} rwkmlx,
|
||||
|
||||
include if exists <abstractions/deny-root-dir-access.d>
|
|
@ -23,3 +23,5 @@
|
|||
@{run}/udev/data/c16[6,7]* r,
|
||||
@{run}/udev/data/c18[0,8,9]* r,
|
||||
@{run}/udev/data/c8[0-9]:[0-9]* r,
|
||||
|
||||
include if exists <abstractions/devices-usb.d>
|
|
@ -81,3 +81,5 @@
|
|||
@{run}/udev/data/c189:[0-9]* r, # for /dev/bus/usb/**
|
||||
|
||||
@{run}/udev/data/+usb:* r, # for ?
|
||||
|
||||
include if exists <abstractions/disks-read.d>
|
|
@ -82,3 +82,5 @@
|
|||
@{run}/udev/data/c189:[0-9]* r, # for /dev/bus/usb/**
|
||||
|
||||
@{run}/udev/data/+usb:* r, # for ?
|
||||
|
||||
include if exists <abstractions/disks-write.d>
|
|
@ -11,3 +11,5 @@
|
|||
deny /etc/fstab r,
|
||||
|
||||
deny /dev/disk/*/ r,
|
||||
|
||||
include if exists <abstractions/file-browsing-strict.d>
|
|
@ -17,3 +17,5 @@
|
|||
/var/lib/snapd/desktop/applications/mimeinfo.cache r,
|
||||
/var/lib/snapd/desktop/applications/*.desktop r,
|
||||
/var/lib/snapd/desktop/applications/ r,
|
||||
|
||||
include if exists <abstractions/flatpak-snap.d>
|
|
@ -40,3 +40,5 @@
|
|||
deny "@{user_share_dirs}/fonts/Google Fonts/.uuid{,.NEW,.LCK,.TMP-*}" w,
|
||||
owner "@{user_share_dirs}/fonts/Google Fonts/**/.uuid" r,
|
||||
deny "@{user_share_dirs}/fonts/Google Fonts/**/.uuid{,.NEW,.LCK,.TMP-*}" w,
|
||||
|
||||
include if exists <abstractions/fontconfig-cache-read.d>
|
|
@ -25,3 +25,4 @@
|
|||
owner "@{user_share_dirs}/fonts/Google Fonts/**/.uuid{,.NEW,.LCK,.TMP-*}" rw,
|
||||
link "@{user_share_dirs}/fonts/Google Fonts/**/.uuid.LCK" -> "/home/*/.local/share/fonts/Google Fonts/**/.uuid.TMP-*",
|
||||
|
||||
include if exists <abstractions/fontconfig-cache-write.d>
|
|
@ -7,3 +7,5 @@
|
|||
owner @{HOME}/.fzf/{,**} r,
|
||||
|
||||
owner @{HOME}/.fzf.* r,
|
||||
|
||||
include if exists <abstractions/fzf.d>
|
|
@ -51,3 +51,5 @@
|
|||
|
||||
owner @{HOME}/{.cache/,.}gstreamer-[0-9]*/ rw,
|
||||
owner @{HOME}/{.cache/,.}gstreamer-[0-9]*/registry.*.bin{,.tmp*} rw,
|
||||
|
||||
include if exists <abstractions/gstreamer.d>
|
|
@ -42,3 +42,5 @@
|
|||
|
||||
# Xsession errors file
|
||||
owner @{HOME}/.xsession-errors w,
|
||||
|
||||
include if exists <abstraction/gtk.d>
|
|
@ -29,3 +29,5 @@
|
|||
owner /var/tmp/kdecache-*/ r,
|
||||
owner /var/tmp/kdecache-*/** r,
|
||||
owner /var/tmp/kdecache-*/*.kcache rw,
|
||||
|
||||
include if exists <abstractions/kde4.d>
|
|
@ -58,3 +58,5 @@
|
|||
#/usr/share/mime/ r,
|
||||
#owner @{user_config_dirs}/menus/ r,
|
||||
#owner @{user_config_dirs}/menus/applications-merged/ r,
|
||||
|
||||
include if exists <abstractions/kde5-plasma5.d>
|
|
@ -20,3 +20,4 @@
|
|||
/{var,}run/systemd/userdb/io.systemd.{NameServiceSwitch,Multiplexer,DynamicUser,Home} r,
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
|
||||
include if exists <abstractions/nameservice-strict.d>
|
|
@ -17,3 +17,5 @@
|
|||
/dev/kmsg w,
|
||||
|
||||
@{sys}/firmware/efi/efivars/SecureBoot-[0-9a-f]*-[0-9a-f]*-[0-9a-f]*-[0-9a-f]*-[0-9a-f]* r,
|
||||
|
||||
include if exists <abstractions/systemd-common.d>
|
|
@ -11,3 +11,5 @@
|
|||
owner @{user_cache_dirs}/thumbnails/ r,
|
||||
owner @{user_cache_dirs}/thumbnails/{large,normal}/ r,
|
||||
owner @{user_cache_dirs}/thumbnails/{large,normal}/[a-f0-9]*.png r,
|
||||
|
||||
include if exists <abstractions/thumbnails-cache-read.d>
|
|
@ -13,3 +13,5 @@
|
|||
owner @{user_cache_dirs}/thumbnails/{large,normal}/ rw,
|
||||
owner @{user_cache_dirs}/thumbnails/{large,normal}/#[0-9]*[0-9] rw,
|
||||
owner @{user_cache_dirs}/thumbnails/{large,normal}/[a-f0-9]*.png rwl -> @{user_cache_dirs}/thumbnails/{large,normal}/#[0-9]*[0-9],
|
||||
|
||||
include if exists <abstractions/thumbnails-cache-write.d>
|
|
@ -29,3 +29,5 @@
|
|||
|
||||
/usr/bin/obfsproxy PUx,
|
||||
/usr/bin/obfs4proxy Pix,
|
||||
|
||||
include if exists <abstractions/tor.d>
|
|
@ -51,3 +51,5 @@
|
|||
/run/udev/data/+usb* r,
|
||||
|
||||
/sys/devices/system/node/*/meminfo r,
|
||||
|
||||
include if exists <abstractions/totem.d>
|
|
@ -74,3 +74,5 @@
|
|||
owner /{media,mnt}/*/*/.Trash-[0-9]*/expunged/[0-9]* rw,
|
||||
owner /{media,mnt}/*/*/.Trash-[0-9]*/expunged/[0-9]*/ rw,
|
||||
owner /{media,mnt}/*/*/.Trash-[0-9]*/expunged/[0-9]*/** rw,
|
||||
|
||||
include if exists <abstractions/trash.d>
|
|
@ -19,3 +19,5 @@
|
|||
# For SSHFS mounts (without owner as files in such mounts can be owned by different users)
|
||||
@{HOME}/mount-sshfs/ r,
|
||||
@{HOME}/mount-sshfs/** rwl,
|
||||
|
||||
include if exists <abstractions/user-download-strict.d>
|
|
@ -8,3 +8,5 @@
|
|||
owner @{HOME}/@{XDG_VIDEOS_DIR}/{,**} r,
|
||||
owner @{HOME}/@{XDG_PROJECTS_DIR}/{,**} r,
|
||||
owner @{HOME}/@{XDG_BOOKS_DIR}/{,**} r,
|
||||
|
||||
include if exists <abstractions/user-read.d>
|
|
@ -12,3 +12,4 @@
|
|||
owner @{user_cache_dirs}/vlc/art/artistalbum/**/art rw,
|
||||
owner @{user_cache_dirs}/vlc/art/artistalbum/**/art.jpg rw,
|
||||
|
||||
include if exists <abstractions/vlc-art-cache-write.d>
|
|
@ -25,3 +25,5 @@
|
|||
|
||||
owner @{HOME}/.zcompdump-* rw,
|
||||
owner @{user_config_dirs}/zsh/{,**} r,
|
||||
|
||||
include if exists <abstractions/zsh.d>
|
Loading…
Add table
Reference in a new issue