mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2025-02-11 04:35:12 +01:00
feat(abs): minor improvement to some abstraction.
Some checks failed
Ubuntu / check (push) Has been cancelled
Ubuntu / build (default, ubuntu-22.04) (push) Has been cancelled
Ubuntu / build (default, ubuntu-24.04) (push) Has been cancelled
Ubuntu / build (full-system-policy, ubuntu-22.04) (push) Has been cancelled
Ubuntu / build (full-system-policy, ubuntu-24.04) (push) Has been cancelled
Ubuntu / tests (push) Has been cancelled
Some checks failed
Ubuntu / check (push) Has been cancelled
Ubuntu / build (default, ubuntu-22.04) (push) Has been cancelled
Ubuntu / build (default, ubuntu-24.04) (push) Has been cancelled
Ubuntu / build (full-system-policy, ubuntu-22.04) (push) Has been cancelled
Ubuntu / build (full-system-policy, ubuntu-24.04) (push) Has been cancelled
Ubuntu / tests (push) Has been cancelled
This commit is contained in:
parent
c29927ea2f
commit
5784ff83cf
8 changed files with 11 additions and 9 deletions
|
@ -21,6 +21,7 @@
|
||||||
@{PROC}/ r,
|
@{PROC}/ r,
|
||||||
@{PROC}/@{pids}/cgroup r,
|
@{PROC}/@{pids}/cgroup r,
|
||||||
@{PROC}/@{pids}/cmdline r,
|
@{PROC}/@{pids}/cmdline r,
|
||||||
|
@{PROC}/@{pids}/environ r,
|
||||||
@{PROC}/@{pids}/stat r,
|
@{PROC}/@{pids}/stat r,
|
||||||
@{PROC}/sys/kernel/osrelease r,
|
@{PROC}/sys/kernel/osrelease r,
|
||||||
@{PROC}/uptime r,
|
@{PROC}/uptime r,
|
||||||
|
|
|
@ -8,6 +8,7 @@
|
||||||
ptrace read peer=@{p_systemd},
|
ptrace read peer=@{p_systemd},
|
||||||
|
|
||||||
@{sys}/firmware/efi/efivars/SecureBoot-@{uuid} r,
|
@{sys}/firmware/efi/efivars/SecureBoot-@{uuid} r,
|
||||||
|
@{sys}/fs/cgroup/system.slice/@{profile_name}.service/ r,
|
||||||
@{sys}/fs/cgroup/system.slice/@{profile_name}.service/memory.pressure rw,
|
@{sys}/fs/cgroup/system.slice/@{profile_name}.service/memory.pressure rw,
|
||||||
|
|
||||||
@{PROC}/1/cgroup r,
|
@{PROC}/1/cgroup r,
|
||||||
|
|
|
@ -10,7 +10,7 @@
|
||||||
dbus receive bus=session path=/ca/desrt/dconf/Writer/user
|
dbus receive bus=session path=/ca/desrt/dconf/Writer/user
|
||||||
interface=ca.desrt.dconf.Writer
|
interface=ca.desrt.dconf.Writer
|
||||||
member=Notify
|
member=Notify
|
||||||
peer=(name=:*, label=dconf-service),
|
peer=(name=@{busname}, label=dconf-service),
|
||||||
|
|
||||||
/usr/share/dconf/profile/gdm r,
|
/usr/share/dconf/profile/gdm r,
|
||||||
|
|
||||||
|
|
|
@ -22,7 +22,7 @@
|
||||||
dbus receive bus=session
|
dbus receive bus=session
|
||||||
interface=org.freedesktop.DBus.Introspectable
|
interface=org.freedesktop.DBus.Introspectable
|
||||||
member=Introspect
|
member=Introspect
|
||||||
peer=(name=:*, label=gnome-shell),
|
peer=(name=@{busname}, label=gnome-shell),
|
||||||
|
|
||||||
/usr/{local/,}share/ r,
|
/usr/{local/,}share/ r,
|
||||||
/usr/{local/,}share/glib-@{version}/schemas/** r,
|
/usr/{local/,}share/glib-@{version}/schemas/** r,
|
||||||
|
|
|
@ -14,7 +14,7 @@
|
||||||
dbus receive bus=session
|
dbus receive bus=session
|
||||||
interface=org.freedesktop.DBus.Introspectable
|
interface=org.freedesktop.DBus.Introspectable
|
||||||
member=Introspect
|
member=Introspect
|
||||||
peer=(name=:*, label=gnome-shell),
|
peer=(name=@{busname}, label=gnome-shell),
|
||||||
|
|
||||||
/usr/share/desktop-base/{,**} r,
|
/usr/share/desktop-base/{,**} r,
|
||||||
/usr/share/hwdata/*.ids r,
|
/usr/share/hwdata/*.ids r,
|
||||||
|
|
|
@ -7,7 +7,7 @@
|
||||||
dbus receive bus=session
|
dbus receive bus=session
|
||||||
interface=org.freedesktop.DBus.Introspectable
|
interface=org.freedesktop.DBus.Introspectable
|
||||||
member=Introspect
|
member=Introspect
|
||||||
peer=(name=:*, label=gnome-shell),
|
peer=(name=@{busname}, label=gnome-shell),
|
||||||
|
|
||||||
/var/cache/gio-@{int}.@{int}/gnome-mimeapps.list r,
|
/var/cache/gio-@{int}.@{int}/gnome-mimeapps.list r,
|
||||||
|
|
||||||
|
|
|
@ -5,7 +5,7 @@
|
||||||
dbus send bus=session
|
dbus send bus=session
|
||||||
interface=org.gtk.Actions
|
interface=org.gtk.Actions
|
||||||
member=DescribeAll
|
member=DescribeAll
|
||||||
peer=(name=:*),
|
peer=(name=@{busname}),
|
||||||
dbus send bus=session
|
dbus send bus=session
|
||||||
interface=org.gtk.Actions
|
interface=org.gtk.Actions
|
||||||
member=DescribeAll
|
member=DescribeAll
|
||||||
|
@ -14,7 +14,7 @@
|
||||||
dbus receive bus=session
|
dbus receive bus=session
|
||||||
interface=org.gtk.Actions
|
interface=org.gtk.Actions
|
||||||
member=Changed
|
member=Changed
|
||||||
peer=(name=:*),
|
peer=(name=@{busname}),
|
||||||
dbus receive bus=session
|
dbus receive bus=session
|
||||||
interface=org.gtk.Actions
|
interface=org.gtk.Actions
|
||||||
member=Changed
|
member=Changed
|
||||||
|
@ -23,11 +23,11 @@
|
||||||
dbus send bus=session path=/org/gtk/Settings
|
dbus send bus=session path=/org/gtk/Settings
|
||||||
interface=org.freedesktop.DBus.Properties
|
interface=org.freedesktop.DBus.Properties
|
||||||
member=GetAll
|
member=GetAll
|
||||||
peer=(name=:*, label=gsd-xsettings),
|
peer=(name=@{busname}, label=gsd-xsettings),
|
||||||
dbus receive bus=session path=/org/gtk/Settings
|
dbus receive bus=session path=/org/gtk/Settings
|
||||||
interface=org.freedesktop.DBus.Properties
|
interface=org.freedesktop.DBus.Properties
|
||||||
member=PropertiesChanged
|
member=PropertiesChanged
|
||||||
peer=(name=:*, label=gsd-xsettings),
|
peer=(name=@{busname}, label=gsd-xsettings),
|
||||||
|
|
||||||
@{lib}/{,@{multiarch}/}gtk*/** mr,
|
@{lib}/{,@{multiarch}/}gtk*/** mr,
|
||||||
|
|
||||||
|
|
|
@ -6,6 +6,6 @@
|
||||||
|
|
||||||
owner @{user_config_dirs}/menus/{,**} r,
|
owner @{user_config_dirs}/menus/{,**} r,
|
||||||
|
|
||||||
owner @{run}/user/@{uid}/kioclient*.@{int}.kioworker.socket rwl -> @{run}/user/@{uid}/#@{int},
|
owner @{run}/user/@{uid}/kioclient@{rand6}.@{int}.kioworker.socket rwl -> @{run}/user/@{uid}/#@{int},
|
||||||
|
|
||||||
# vim:syntax=apparmor
|
# vim:syntax=apparmor
|
||||||
|
|
Loading…
Reference in a new issue