feat(profile): clean superfluous openssl abstraction includes

apparmor.d equivalent of https://gitlab.com/apparmor/apparmor/-/merge_requests/1179
This commit is contained in:
Alexandre Pujol 2024-03-12 16:00:44 +00:00
parent d5972cdf1d
commit 467c38724a
Failed to generate hash of commit
173 changed files with 0 additions and 180 deletions

View file

@ -24,7 +24,6 @@
include <abstractions/graphics> include <abstractions/graphics>
include <abstractions/gstreamer> include <abstractions/gstreamer>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/p11-kit> include <abstractions/p11-kit>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
include <abstractions/video> include <abstractions/video>

View file

@ -20,7 +20,6 @@ profile default @{exec_path} flags=(attach_disconnected,mediate_deleted) {
include <abstractions/devices-usb> include <abstractions/devices-usb>
include <abstractions/graphics> include <abstractions/graphics>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/p11-kit> include <abstractions/p11-kit>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
include <abstractions/video> include <abstractions/video>

View file

@ -13,7 +13,6 @@ profile akonadi_maildispatcher_agent @{exec_path} {
include <abstractions/freedesktop.org> include <abstractions/freedesktop.org>
include <abstractions/graphics> include <abstractions/graphics>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/qt5> include <abstractions/qt5>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
include <abstractions/X-strict> include <abstractions/X-strict>

View file

@ -29,7 +29,6 @@ profile calibre @{exec_path} {
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/nvidia> include <abstractions/nvidia>
include <abstractions/opencl-intel> include <abstractions/opencl-intel>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
include <abstractions/qt5-compose-cache-write> include <abstractions/qt5-compose-cache-write>
include <abstractions/qt5-settings-write> include <abstractions/qt5-settings-write>

View file

@ -22,7 +22,6 @@ profile dropbox @{exec_path} {
include <abstractions/python> include <abstractions/python>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/qt5-settings-write> include <abstractions/qt5-settings-write>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
ptrace peer=@{profile_name}, ptrace peer=@{profile_name},

View file

@ -22,7 +22,6 @@ profile flameshot @{exec_path} {
include <abstractions/thumbnails-cache-read> include <abstractions/thumbnails-cache-read>
include <abstractions/user-download-strict> include <abstractions/user-download-strict>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
network inet dgram, network inet dgram,

View file

@ -27,7 +27,6 @@ profile telegram-desktop @{exec_path} {
include <abstractions/mesa> include <abstractions/mesa>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/enchant> include <abstractions/enchant>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
network inet dgram, network inet dgram,

View file

@ -17,7 +17,6 @@ profile apt @{exec_path} flags=(attach_disconnected) {
include <abstractions/bus/org.freedesktop.PolicyKit1> include <abstractions/bus/org.freedesktop.PolicyKit1>
include <abstractions/consoles> include <abstractions/consoles>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>

View file

@ -13,7 +13,6 @@ profile apt-listbugs @{exec_path} {
include <abstractions/consoles> include <abstractions/consoles>
include <abstractions/ruby> include <abstractions/ruby>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
#capability sys_tty_config, #capability sys_tty_config,

View file

@ -13,7 +13,6 @@ profile debsecan @{exec_path} {
include <abstractions/consoles> include <abstractions/consoles>
include <abstractions/python> include <abstractions/python>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
network inet dgram, network inet dgram,

View file

@ -16,7 +16,6 @@ profile querybts @{exec_path} {
include <abstractions/freedesktop.org> include <abstractions/freedesktop.org>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/python> include <abstractions/python>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
include <abstractions/apt-common> include <abstractions/apt-common>

View file

@ -17,7 +17,6 @@ profile unattended-upgrade @{exec_path} flags=(attach_disconnected) {
include <abstractions/bus/org.freedesktop.PackageKit> include <abstractions/bus/org.freedesktop.PackageKit>
include <abstractions/consoles> include <abstractions/consoles>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
capability chown, capability chown,

View file

@ -19,7 +19,6 @@ profile firefox-crashreporter @{exec_path} flags=(attach_disconnected) {
include <abstractions/desktop> include <abstractions/desktop>
include <abstractions/fontconfig-cache-read> include <abstractions/fontconfig-cache-read>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
signal (receive) set=(term, kill) peer=firefox, signal (receive) set=(term, kill) peer=firefox,

View file

@ -15,7 +15,6 @@ include <tunables/global>
profile firefox-pingsender @{exec_path} { profile firefox-pingsender @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
network inet stream, network inet stream,

View file

@ -18,7 +18,6 @@ profile opera-crashreporter @{exec_path} {
include <abstractions/fonts> include <abstractions/fonts>
include <abstractions/freedesktop.org> include <abstractions/freedesktop.org>
include <abstractions/nameservice> include <abstractions/nameservice>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
ptrace (trace, read) peer=opera, ptrace (trace, read) peer=opera,

View file

@ -15,7 +15,6 @@ profile colord @{exec_path} flags=(attach_disconnected) {
include <abstractions/bus/org.freedesktop.PolicyKit1> include <abstractions/bus/org.freedesktop.PolicyKit1>
include <abstractions/devices-usb> include <abstractions/devices-usb>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
network inet dgram, network inet dgram,
network inet6 dgram, network inet6 dgram,

View file

@ -27,7 +27,6 @@ profile pulseaudio @{exec_path} {
include <abstractions/gstreamer> include <abstractions/gstreamer>
include <abstractions/hosts_access> include <abstractions/hosts_access>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/X-strict> include <abstractions/X-strict>
ptrace (trace) peer=@{profile_name}, ptrace (trace) peer=@{profile_name},

View file

@ -11,7 +11,6 @@ profile chrome-gnome-shell @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/dconf-write> include <abstractions/dconf-write>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>

View file

@ -17,7 +17,6 @@ profile evolution-alarm-notify @{exec_path} {
include <abstractions/gnome-strict> include <abstractions/gnome-strict>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/graphics> include <abstractions/graphics>
include <abstractions/openssl>
network netlink raw, network netlink raw,

View file

@ -13,7 +13,6 @@ profile gdm-xsession @{exec_path} {
include <abstractions/consoles> include <abstractions/consoles>
include <abstractions/dconf-write> include <abstractions/dconf-write>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
@{exec_path} mr, @{exec_path} mr,

View file

@ -23,7 +23,6 @@ profile gjs-console @{exec_path} flags=(attach_disconnected) {
include <abstractions/gnome-strict> include <abstractions/gnome-strict>
include <abstractions/graphics> include <abstractions/graphics>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
network netlink raw, network netlink raw,

View file

@ -21,7 +21,6 @@ profile gnome-calendar @{exec_path} {
include <abstractions/gnome-strict> include <abstractions/gnome-strict>
include <abstractions/graphics> include <abstractions/graphics>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/p11-kit> include <abstractions/p11-kit>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>

View file

@ -18,7 +18,6 @@ profile gnome-contacts @{exec_path} {
include <abstractions/graphics> include <abstractions/graphics>
include <abstractions/gstreamer> include <abstractions/gstreamer>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
network netlink raw, network netlink raw,

View file

@ -13,7 +13,6 @@ profile gnome-contacts-search-provider @{exec_path} {
include <abstractions/dconf-write> include <abstractions/dconf-write>
include <abstractions/gnome-strict> include <abstractions/gnome-strict>
include <abstractions/graphics> include <abstractions/graphics>
include <abstractions/openssl>
signal (send) set=(term) peer=unconfined, signal (send) set=(term) peer=unconfined,

View file

@ -19,7 +19,6 @@ profile gnome-control-center-goa-helper @{exec_path} {
include <abstractions/gnome-strict> include <abstractions/gnome-strict>
include <abstractions/graphics> include <abstractions/graphics>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/p11-kit> include <abstractions/p11-kit>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>

View file

@ -21,7 +21,6 @@ profile gnome-extension-gsconnect @{exec_path} {
include <abstractions/freedesktop.org> include <abstractions/freedesktop.org>
include <abstractions/gtk> include <abstractions/gtk>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/p11-kit> include <abstractions/p11-kit>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>

View file

@ -15,7 +15,6 @@ profile gnome-keyring-daemon @{exec_path} flags=(attach_disconnected) {
include <abstractions/bus/org.freedesktop.login1.Session> include <abstractions/bus/org.freedesktop.login1.Session>
include <abstractions/bus/org.freedesktop.portal.Desktop> include <abstractions/bus/org.freedesktop.portal.Desktop>
include <abstractions/bus/org.gnome.SessionManager> include <abstractions/bus/org.gnome.SessionManager>
include <abstractions/openssl>
capability ipc_lock, capability ipc_lock,

View file

@ -15,7 +15,6 @@ profile gnome-music @{exec_path} flags=(attach_disconnected) {
include <abstractions/graphics> include <abstractions/graphics>
include <abstractions/gstreamer> include <abstractions/gstreamer>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/p11-kit> include <abstractions/p11-kit>
include <abstractions/python> include <abstractions/python>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>

View file

@ -12,7 +12,6 @@ profile gnome-remote-desktop-daemon @{exec_path} {
include <abstractions/bus-session> include <abstractions/bus-session>
include <abstractions/dconf-write> include <abstractions/dconf-write>
include <abstractions/graphics> include <abstractions/graphics>
include <abstractions/openssl>
network inet stream, network inet stream,
network inet6 stream, network inet6 stream,

View file

@ -14,7 +14,6 @@ profile gnome-software @{exec_path} {
include <abstractions/gnome-strict> include <abstractions/gnome-strict>
include <abstractions/graphics> include <abstractions/graphics>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/p11-kit> include <abstractions/p11-kit>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>

View file

@ -15,7 +15,6 @@ profile goa-daemon @{exec_path} {
include <abstractions/dconf-write> include <abstractions/dconf-write>
include <abstractions/gnome-strict> include <abstractions/gnome-strict>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/p11-kit> include <abstractions/p11-kit>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>

View file

@ -24,7 +24,6 @@ profile nautilus @{exec_path} flags=(attach_disconnected) {
include <abstractions/gnome-strict> include <abstractions/gnome-strict>
include <abstractions/graphics> include <abstractions/graphics>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/trash> include <abstractions/trash>
# userns, # userns,

View file

@ -18,7 +18,6 @@ profile org.gnome.NautilusPreviewer @{exec_path} {
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/private-files-strict> include <abstractions/private-files-strict>
include <abstractions/video> include <abstractions/video>
include <abstractions/openssl>
network netlink raw, network netlink raw,

View file

@ -18,7 +18,6 @@ profile seahorse @{exec_path} {
include <abstractions/bus/org.freedesktop.secrets> include <abstractions/bus/org.freedesktop.secrets>
include <abstractions/dconf-write> include <abstractions/dconf-write>
include <abstractions/gnome-strict> include <abstractions/gnome-strict>
include <abstractions/openssl>
include <abstractions/p11-kit> include <abstractions/p11-kit>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>

View file

@ -21,7 +21,6 @@ profile tracker-extract @{exec_path} flags=(attach_disconnected) {
include <abstractions/graphics> include <abstractions/graphics>
include <abstractions/gstreamer> include <abstractions/gstreamer>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
network netlink raw, network netlink raw,

View file

@ -12,7 +12,6 @@ profile kiod @{exec_path} {
include <abstractions/graphics> include <abstractions/graphics>
include <abstractions/kde-strict> include <abstractions/kde-strict>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
network netlink raw, network netlink raw,

View file

@ -14,7 +14,6 @@ profile kioworker @{exec_path} {
include <abstractions/graphics> include <abstractions/graphics>
include <abstractions/kde-strict> include <abstractions/kde-strict>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
include <abstractions/thumbnails-cache-write> include <abstractions/thumbnails-cache-write>
include <abstractions/trash> include <abstractions/trash>

View file

@ -14,7 +14,6 @@ profile plasma-discover @{exec_path} {
include <abstractions/graphics> include <abstractions/graphics>
include <abstractions/kde-strict> include <abstractions/kde-strict>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/qt5-shader-cache> include <abstractions/qt5-shader-cache>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>

View file

@ -93,7 +93,6 @@ profile sddm-xsession @{exec_path} {
profile gpg { profile gpg {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
capability dac_read_search, capability dac_read_search,

View file

@ -12,7 +12,6 @@ profile xdm-xsession @{exec_path} {
include <abstractions/bash> include <abstractions/bash>
include <abstractions/dconf-write> include <abstractions/dconf-write>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/X-strict> include <abstractions/X-strict>
@{exec_path} mr, @{exec_path} mr,

View file

@ -18,7 +18,6 @@ profile NetworkManager @{exec_path} flags=(attach_disconnected) {
include <abstractions/bus/org.freedesktop.PolicyKit1> include <abstractions/bus/org.freedesktop.PolicyKit1>
include <abstractions/bus/org.freedesktop.resolve1> include <abstractions/bus/org.freedesktop.resolve1>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
capability audit_write, capability audit_write,

View file

@ -11,7 +11,6 @@ profile networkd-dispatcher @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/bus-system> include <abstractions/bus-system>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
dbus receive bus=system path=/org/freedesktop/network1{,/link/*} dbus receive bus=system path=/org/freedesktop/network1{,/link/*}

View file

@ -26,7 +26,6 @@ include <tunables/global>
profile openvpn @{exec_path} flags=(attach_disconnected) { profile openvpn @{exec_path} flags=(attach_disconnected) {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
# Needed to remove the following errors: # Needed to remove the following errors:
# ERROR: Cannot ioctl TUNSETIFF tun: Operation not permitted (errno=1) # ERROR: Cannot ioctl TUNSETIFF tun: Operation not permitted (errno=1)

View file

@ -10,7 +10,6 @@ include <tunables/global>
profile arch-audit @{exec_path} { profile arch-audit @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
capability dac_read_search, capability dac_read_search,

View file

@ -11,7 +11,6 @@ profile aurpublish @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
include <abstractions/openssl>
network inet dgram, network inet dgram,
network inet6 dgram, network inet6 dgram,

View file

@ -10,7 +10,6 @@ include <tunables/global>
profile paccache @{exec_path} flags=(attach_disconnected) { profile paccache @{exec_path} flags=(attach_disconnected) {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
capability dac_read_search, capability dac_read_search,
capability mknod, capability mknod,

View file

@ -12,7 +12,6 @@ profile pacman @{exec_path} {
include <abstractions/consoles> include <abstractions/consoles>
include <abstractions/disks-read> include <abstractions/disks-read>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
capability audit_write, capability audit_write,
@ -169,7 +168,6 @@ profile pacman @{exec_path} {
profile gpg { profile gpg {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
capability dac_read_search, capability dac_read_search,

View file

@ -50,7 +50,6 @@ profile pacman-hook-mkinitcpio @{exec_path} flags=(attach_disconnected) {
profile pacman { profile pacman {
include <abstractions/base> include <abstractions/base>
include <abstractions/openssl>
capability dac_read_search, capability dac_read_search,

View file

@ -10,7 +10,6 @@ include <tunables/global>
profile reflector @{exec_path} flags=(attach_disconnected) { profile reflector @{exec_path} flags=(attach_disconnected) {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>

View file

@ -10,7 +10,6 @@ include <tunables/global>
@{exec_path} += @{lib}/ssh/sftp-server @{exec_path} += @{lib}/ssh/sftp-server
profile sftp-server @{exec_path} { profile sftp-server @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/openssl>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
capability dac_read_search, capability dac_read_search,

View file

@ -12,7 +12,6 @@ profile ssh @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/consoles> include <abstractions/consoles>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
signal (receive) set=(term) peer=gnome-keyring-daemon, signal (receive) set=(term) peer=gnome-keyring-daemon,

View file

@ -11,7 +11,6 @@ include <tunables/global>
profile ssh-agent @{exec_path} { profile ssh-agent @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
signal (receive) set=term peer=cockpit-bridge, signal (receive) set=term peer=cockpit-bridge,
signal (receive) set=term peer=gnome-keyring-daemon, signal (receive) set=term peer=gnome-keyring-daemon,

View file

@ -13,7 +13,6 @@ profile ssh-keygen @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/consoles> include <abstractions/consoles>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
@{exec_path} mr, @{exec_path} mr,

View file

@ -23,7 +23,6 @@ profile sshd @{exec_path} flags=(attach_disconnected) {
include <abstractions/consoles> include <abstractions/consoles>
include <abstractions/hosts_access> include <abstractions/hosts_access>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
include <abstractions/wutmp> include <abstractions/wutmp>

View file

@ -47,7 +47,6 @@ profile coredumpctl @{exec_path} flags=(complain) {
profile gdb { profile gdb {
include <abstractions/base> include <abstractions/base>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
ptrace (trace), ptrace (trace),

View file

@ -11,7 +11,6 @@ include <tunables/global>
profile systemd-coredump @{exec_path} flags=(attach_disconnected,mediate_deleted) { profile systemd-coredump @{exec_path} flags=(attach_disconnected,mediate_deleted) {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/systemd-common> include <abstractions/systemd-common>
# userns, # userns,

View file

@ -11,7 +11,6 @@ profile systemd-cryptsetup @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/systemd-common> include <abstractions/systemd-common>
include <abstractions/disks-write> include <abstractions/disks-write>
include <abstractions/openssl>
capability ipc_lock, capability ipc_lock,
capability net_admin, capability net_admin,

View file

@ -12,7 +12,6 @@ profile systemd-homed @{exec_path} flags=(attach_disconnected) {
include <abstractions/bus-system> include <abstractions/bus-system>
include <abstractions/disks-write> include <abstractions/disks-write>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/systemd-common> include <abstractions/systemd-common>
capability chown, capability chown,

View file

@ -12,7 +12,6 @@ profile systemd-resolved @{exec_path} flags=(attach_disconnected) {
include <abstractions/bus-system> include <abstractions/bus-system>
include <abstractions/bus/org.freedesktop.login1> include <abstractions/bus/org.freedesktop.login1>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/p11-kit> include <abstractions/p11-kit>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
include <abstractions/systemd-common> include <abstractions/systemd-common>

View file

@ -13,7 +13,6 @@ profile apport @{exec_path} flags=(attach_disconnected) {
include <abstractions/bus-session> include <abstractions/bus-session>
include <abstractions/bus/org.gnome.SessionManager> include <abstractions/bus/org.gnome.SessionManager>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
capability chown, capability chown,

View file

@ -10,7 +10,6 @@ include <tunables/global>
profile apport-checkreports @{exec_path} flags=(attach_disconnected) { profile apport-checkreports @{exec_path} flags=(attach_disconnected) {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
@{exec_path} mr, @{exec_path} mr,

View file

@ -17,7 +17,6 @@ profile apport-gtk @{exec_path} {
include <abstractions/dconf-write> include <abstractions/dconf-write>
include <abstractions/gnome-strict> include <abstractions/gnome-strict>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>

View file

@ -16,7 +16,6 @@ profile check-new-release-gtk @{exec_path} {
include <abstractions/dconf-write> include <abstractions/dconf-write>
include <abstractions/gnome-strict> include <abstractions/gnome-strict>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>

View file

@ -12,7 +12,6 @@ profile do-release-upgrade @{exec_path} {
include <abstractions/apt-common> include <abstractions/apt-common>
include <abstractions/consoles> include <abstractions/consoles>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>

View file

@ -11,7 +11,6 @@ profile hwe-support-status @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/apt-common> include <abstractions/apt-common>
include <abstractions/python> include <abstractions/python>
include <abstractions/openssl>
@{exec_path} mr, @{exec_path} mr,

View file

@ -10,7 +10,6 @@ include <tunables/global>
profile list-oem-metapackages @{exec_path} { profile list-oem-metapackages @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/python> include <abstractions/python>
include <abstractions/openssl>
include <abstractions/apt-common> include <abstractions/apt-common>
@{exec_path} mr, @{exec_path} mr,

View file

@ -12,7 +12,6 @@ profile software-properties-dbus @{exec_path} {
include <abstractions/apt-common> include <abstractions/apt-common>
include <abstractions/bus-system> include <abstractions/bus-system>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
# dbus: own bus=system name=com.ubuntu.SoftwareProperties # dbus: own bus=system name=com.ubuntu.SoftwareProperties

View file

@ -18,7 +18,6 @@ profile software-properties-gtk @{exec_path} {
include <abstractions/dconf-write> include <abstractions/dconf-write>
include <abstractions/gnome-strict> include <abstractions/gnome-strict>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
dbus bind bus=session name=com.ubuntu.SoftwareProperties, dbus bind bus=session name=com.ubuntu.SoftwareProperties,

View file

@ -12,7 +12,6 @@ profile subiquity-console-conf @{exec_path} {
include <abstractions/disks-read> include <abstractions/disks-read>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/python> include <abstractions/python>
include <abstractions/openssl>
capability chown, capability chown,
capability fsetid, capability fsetid,

View file

@ -12,7 +12,6 @@ profile ubuntu-advantage @{exec_path} {
include <abstractions/apt-common> include <abstractions/apt-common>
include <abstractions/consoles> include <abstractions/consoles>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>

View file

@ -23,7 +23,6 @@ profile update-manager @{exec_path} flags=(attach_disconnected) {
include <abstractions/dconf-write> include <abstractions/dconf-write>
include <abstractions/gnome-strict> include <abstractions/gnome-strict>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>

View file

@ -12,7 +12,6 @@ profile update-motd-updates-available @{exec_path} {
include <abstractions/apt-common> include <abstractions/apt-common>
include <abstractions/consoles> include <abstractions/consoles>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
capability dac_read_search, capability dac_read_search,

View file

@ -19,7 +19,6 @@ profile update-notifier @{exec_path} {
include <abstractions/dconf-write> include <abstractions/dconf-write>
include <abstractions/gnome-strict> include <abstractions/gnome-strict>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
unix (bind) type=stream addr=@@{hex}/bus/systemd/bus-api-user, unix (bind) type=stream addr=@@{hex}/bus/systemd/bus-api-user,

View file

@ -12,7 +12,6 @@ profile cockpit-bridge @{exec_path} {
include <abstractions/app-launcher-root> include <abstractions/app-launcher-root>
include <abstractions/consoles> include <abstractions/consoles>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
capability dac_read_search, capability dac_read_search,

View file

@ -10,7 +10,6 @@ include <tunables/global>
profile cockpit-certificate-helper @{exec_path} { profile cockpit-certificate-helper @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
@{exec_path} mr, @{exec_path} mr,

View file

@ -10,7 +10,6 @@ include <tunables/global>
profile libvirt-dbus @{exec_path} { profile libvirt-dbus @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
@{exec_path} mr, @{exec_path} mr,

View file

@ -22,7 +22,6 @@ profile libvirtd @{exec_path} flags=(attach_disconnected) {
include <abstractions/devices-usb> include <abstractions/devices-usb>
include <abstractions/disks-write> include <abstractions/disks-write>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
capability audit_write, capability audit_write,
capability bpf, capability bpf,

View file

@ -10,7 +10,6 @@ include <tunables/global>
@{exec_path} = @{lib}/libvirt/virt-aa-helper @{exec_path} = @{lib}/libvirt/virt-aa-helper
profile virt-aa-helper @{exec_path} { profile virt-aa-helper @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/openssl>
capability dac_override, capability dac_override,
capability dac_read_search, capability dac_read_search,

View file

@ -10,7 +10,6 @@ include <tunables/global>
profile virtinterfaced @{exec_path} flags=(attach_disconnected) { profile virtinterfaced @{exec_path} flags=(attach_disconnected) {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
network netlink raw, network netlink raw,

View file

@ -10,7 +10,6 @@ include <tunables/global>
profile virtlogd @{exec_path} flags=(attach_disconnected) { profile virtlogd @{exec_path} flags=(attach_disconnected) {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
ptrace (read) peer=libvirtd, ptrace (read) peer=libvirtd,
ptrace (read) peer=unconfined, ptrace (read) peer=unconfined,

View file

@ -9,7 +9,6 @@ include <tunables/global>
@{exec_path} = @{bin}/virtnetworkd @{exec_path} = @{bin}/virtnetworkd
profile virtnetworkd @{exec_path} flags=(attach_disconnected) { profile virtnetworkd @{exec_path} flags=(attach_disconnected) {
include <abstractions/base> include <abstractions/base>
include <abstractions/openssl>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
network netlink raw, network netlink raw,

View file

@ -13,7 +13,6 @@ profile virtnodedevd @{exec_path} flags=(attach_disconnected) {
include <abstractions/disks-read> include <abstractions/disks-read>
include <abstractions/freedesktop.org> include <abstractions/freedesktop.org>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
capability net_admin, capability net_admin,
capability sys_admin, capability sys_admin,

View file

@ -10,7 +10,6 @@ include <tunables/global>
profile virtsecretd @{exec_path} flags=(attach_disconnected) { profile virtsecretd @{exec_path} flags=(attach_disconnected) {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
network netlink raw, network netlink raw,

View file

@ -12,7 +12,6 @@ include <tunables/global>
profile virtstoraged @{exec_path} flags=(attach_disconnected) { profile virtstoraged @{exec_path} flags=(attach_disconnected) {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
capability dac_read_search, capability dac_read_search,

View file

@ -141,7 +141,6 @@ profile anyremote @{exec_path} {
profile curl { profile curl {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
@{bin}/curl mr, @{bin}/curl mr,

View file

@ -65,7 +65,6 @@ profile appstreamcli @{exec_path} flags=(complain) {
profile curl { profile curl {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
@{bin}/curl mr, @{bin}/curl mr,

View file

@ -19,7 +19,6 @@ profile birdtray @{exec_path} {
include <abstractions/mesa> include <abstractions/mesa>
include <abstractions/dri-enumerate> include <abstractions/dri-enumerate>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
network inet dgram, network inet dgram,

View file

@ -15,7 +15,6 @@ profile conky @{exec_path} {
include <abstractions/fonts> include <abstractions/fonts>
include <abstractions/fontconfig-cache-read> include <abstractions/fontconfig-cache-read>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
# To get the external IP address # To get the external IP address
@ -155,7 +154,6 @@ profile conky @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/consoles> include <abstractions/consoles>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
network inet dgram, network inet dgram,

View file

@ -12,7 +12,6 @@ profile cupsd @{exec_path} flags=(attach_disconnected) {
include <abstractions/bus/org.freedesktop.Avahi> include <abstractions/bus/org.freedesktop.Avahi>
include <abstractions/bus/org.freedesktop.ColorManager> include <abstractions/bus/org.freedesktop.ColorManager>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
capability audit_write, capability audit_write,

View file

@ -12,7 +12,6 @@ profile ddclient @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/perl> include <abstractions/perl>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
@{exec_path} r, @{exec_path} r,

View file

@ -11,7 +11,6 @@ include <tunables/global>
profile dhclient @{exec_path} { profile dhclient @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
capability net_admin, capability net_admin,
capability net_bind_service, capability net_bind_service,

View file

@ -11,7 +11,6 @@ include <tunables/global>
profile dhclient-script @{exec_path} { profile dhclient-script @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice> include <abstractions/nameservice>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
capability net_admin, capability net_admin,

View file

@ -12,7 +12,6 @@ profile dig @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/consoles> include <abstractions/consoles>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
capability dac_override, capability dac_override,
capability dac_read_search, capability dac_read_search,

View file

@ -13,7 +13,6 @@ profile dkms @{exec_path} flags=(attach_disconnected) {
include <abstractions/base> include <abstractions/base>
include <abstractions/consoles> include <abstractions/consoles>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
capability dac_read_search, capability dac_read_search,
capability mknod, capability mknod,
@ -118,7 +117,6 @@ profile dkms @{exec_path} flags=(attach_disconnected) {
profile kmod { profile kmod {
include <abstractions/base> include <abstractions/base>
include <abstractions/consoles> include <abstractions/consoles>
include <abstractions/openssl>
@{bin}/kmod mr, @{bin}/kmod mr,

View file

@ -10,7 +10,6 @@ include <tunables/global>
profile downloadhelper @{exec_path} { profile downloadhelper @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/user-download-strict> include <abstractions/user-download-strict>
network inet dgram, network inet dgram,

View file

@ -17,7 +17,6 @@ profile evince @{exec_path} {
include <abstractions/gnome-strict> include <abstractions/gnome-strict>
include <abstractions/ibus> include <abstractions/ibus>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/user-download-strict> include <abstractions/user-download-strict>
include <abstractions/user-read> include <abstractions/user-read>
include <abstractions/user-write> include <abstractions/user-write>

View file

@ -10,7 +10,6 @@ include <tunables/global>
profile fail2ban-server @{exec_path} flags=(attach_disconnected) { profile fail2ban-server @{exec_path} flags=(attach_disconnected) {
include <abstractions/base> include <abstractions/base>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/python> include <abstractions/python>
capability dac_read_search, capability dac_read_search,

View file

@ -14,7 +14,6 @@ profile firewalld @{exec_path} {
include <abstractions/bus/org.freedesktop.PolicyKit1> include <abstractions/bus/org.freedesktop.PolicyKit1>
include <abstractions/bus/org.freedesktop.NetworkManager> include <abstractions/bus/org.freedesktop.NetworkManager>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
capability mknod, capability mknod,
capability net_admin, capability net_admin,

View file

@ -16,7 +16,6 @@ profile flatpak @{exec_path} flags=(attach_disconnected,mediate_deleted,complain
include <abstractions/dconf-write> include <abstractions/dconf-write>
include <abstractions/gnome-strict> include <abstractions/gnome-strict>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs> include <abstractions/ssl_certs>
# userns, # userns,

View file

@ -9,7 +9,6 @@ include <tunables/global>
@{exec_path} = @{lib}/flatpak-oci-authenticator @{exec_path} = @{lib}/flatpak-oci-authenticator
profile flatpak-oci-authenticator @{exec_path} { profile flatpak-oci-authenticator @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/openssl>
@{exec_path} mr, @{exec_path} mr,

Some files were not shown because too many files have changed in this diff Show more