mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2025-01-18 17:08:09 +01:00
feat(abs): internal cleanup.
This commit is contained in:
parent
5c6f9c51b5
commit
4f1f34de3f
6 changed files with 20 additions and 11 deletions
|
@ -5,6 +5,8 @@
|
||||||
# Provide access to audio devices. It should only be used by audio servers that
|
# Provide access to audio devices. It should only be used by audio servers that
|
||||||
# need direct access to them.
|
# need direct access to them.
|
||||||
|
|
||||||
|
include <abstractions/audio-client>
|
||||||
|
|
||||||
/usr/share/alsa/{,**} r,
|
/usr/share/alsa/{,**} r,
|
||||||
|
|
||||||
/etc/alsa/conf.d/{,**} r,
|
/etc/alsa/conf.d/{,**} r,
|
||||||
|
|
|
@ -27,4 +27,9 @@
|
||||||
member=Introspect
|
member=Introspect
|
||||||
peer=(name=:*, label=systemd-logind),
|
peer=(name=:*, label=systemd-logind),
|
||||||
|
|
||||||
|
dbus send bus=system path=/org/freedesktop/login1/session/*
|
||||||
|
interface=org.freedesktop.login1.Session
|
||||||
|
member=PauseDeviceComplete
|
||||||
|
peer=(name=org.freedesktop.login1, label=systemd-logind),
|
||||||
|
|
||||||
include if exists <abstractions/bus/org.freedesktop.login1.d>
|
include if exists <abstractions/bus/org.freedesktop.login1.d>
|
||||||
|
|
|
@ -8,14 +8,11 @@
|
||||||
|
|
||||||
# userns,
|
# userns,
|
||||||
|
|
||||||
# Only needed when kernel.unprivileged_userns_clone is set to "1"
|
capability setgid, # If kernel.unprivileged_userns_clone = 1
|
||||||
|
capability setuid, # If kernel.unprivileged_userns_clone = 1
|
||||||
capability sys_admin,
|
capability sys_admin,
|
||||||
capability sys_chroot,
|
capability sys_chroot,
|
||||||
capability setuid,
|
capability sys_ptrace,
|
||||||
capability setgid,
|
|
||||||
owner @{PROC}/@{pid}/setgroups w,
|
|
||||||
owner @{PROC}/@{pid}/gid_map w,
|
|
||||||
owner @{PROC}/@{pid}/uid_map w,
|
|
||||||
|
|
||||||
owner @{HOME}/.pki/ rw,
|
owner @{HOME}/.pki/ rw,
|
||||||
owner @{HOME}/.pki/nssdb/ rw,
|
owner @{HOME}/.pki/nssdb/ rw,
|
||||||
|
@ -37,4 +34,9 @@
|
||||||
/dev/shm/ r,
|
/dev/shm/ r,
|
||||||
owner /dev/shm/.org.chromium.Chromium.* rw,
|
owner /dev/shm/.org.chromium.Chromium.* rw,
|
||||||
|
|
||||||
|
# If kernel.unprivileged_userns_clone = 1
|
||||||
|
owner @{PROC}/@{pid}/setgroups w,
|
||||||
|
owner @{PROC}/@{pid}/gid_map w,
|
||||||
|
owner @{PROC}/@{pid}/uid_map w,
|
||||||
|
|
||||||
include if exists <abstractions/common/chromium.d>
|
include if exists <abstractions/common/chromium.d>
|
|
@ -5,6 +5,6 @@
|
||||||
|
|
||||||
owner @{user_cache_dirs}/thumbnails/ r,
|
owner @{user_cache_dirs}/thumbnails/ r,
|
||||||
owner @{user_cache_dirs}/thumbnails/{*large,normal}/ r,
|
owner @{user_cache_dirs}/thumbnails/{*large,normal}/ r,
|
||||||
owner @{user_cache_dirs}/thumbnails/{*large,normal}/@{hex32}.png r,
|
owner @{user_cache_dirs}/thumbnails/{*large,normal}/*.png r,
|
||||||
|
|
||||||
include if exists <abstractions/thumbnails-cache-read.d>
|
include if exists <abstractions/thumbnails-cache-read.d>
|
|
@ -5,8 +5,8 @@
|
||||||
|
|
||||||
owner @{user_cache_dirs}/thumbnails/ rw,
|
owner @{user_cache_dirs}/thumbnails/ rw,
|
||||||
owner @{user_cache_dirs}/thumbnails/{large,normal}/ rw,
|
owner @{user_cache_dirs}/thumbnails/{large,normal}/ rw,
|
||||||
owner @{user_cache_dirs}/thumbnails/{large,normal}/@{hex32}.png rwl -> @{user_cache_dirs}/thumbnails/{large,normal}/#@{int},
|
owner @{user_cache_dirs}/thumbnails/{large,normal}/*.png rwl -> @{user_cache_dirs}/thumbnails/{large,normal}/#@{int},
|
||||||
owner @{user_cache_dirs}/thumbnails/{large,normal}/@{hex32}.png.@{rand6} rw,
|
owner @{user_cache_dirs}/thumbnails/{large,normal}/*.png.@{rand6} rw,
|
||||||
owner @{user_cache_dirs}/thumbnails/{large,normal}/#@{int} rw,
|
owner @{user_cache_dirs}/thumbnails/{large,normal}/#@{int} rw,
|
||||||
|
|
||||||
include if exists <abstractions/thumbnails-cache-write.d>
|
include if exists <abstractions/thumbnails-cache-write.d>
|
|
@ -8,8 +8,8 @@
|
||||||
include <abstractions/wayland>
|
include <abstractions/wayland>
|
||||||
include <abstractions/X-strict>
|
include <abstractions/X-strict>
|
||||||
|
|
||||||
owner @{user_config_dirs}/xfce4/help.rc rw,
|
owner @{user_config_dirs}/xfce4/help{,ers}.rc rw,
|
||||||
owner @{user_config_dirs}/xfce4/help.rc.@{int}.tmp rw,
|
owner @{user_config_dirs}/xfce4/help{,ers}.rc.@{int}.tmp rw,
|
||||||
|
|
||||||
owner @{HOME}/.local/ rw,
|
owner @{HOME}/.local/ rw,
|
||||||
owner @{user_cache_dirs}/ rw,
|
owner @{user_cache_dirs}/ rw,
|
||||||
|
|
Loading…
Reference in a new issue