feat(profile): improve sqlite temp file definition.

This commit is contained in:
Alexandre Pujol 2024-06-15 16:42:32 +01:00
parent 035e1da7b2
commit 79eed4b93d
Failed to generate hash of commit
10 changed files with 16 additions and 16 deletions

View file

@ -58,7 +58,7 @@ profile dropbox @{exec_path} {
# Dropbox first tries the /tmp/ dir, and if it's denied it uses the /var/tmp/ dir instead
owner @{tmp}/dropbox-antifreeze-* rw,
owner @{tmp}/#@{int} rw,
owner /var/tmp/etilqs_@{hex} rw,
owner /var/tmp/etilqs_@{hex16} rw,
@{run}/systemd/users/@{uid} r,

View file

@ -65,8 +65,8 @@ profile tracker-miner @{exec_path} flags=(attach_disconnected) {
owner @{gdm_config_dirs}/dconf/user r,
owner @{gdm_share_dirs}/applications/ r,
owner /var/tmp/etilqs_@{hex} rw,
owner @{tmp}/etilqs_@{hex} rw,
owner /var/tmp/etilqs_@{hex16} rw,
owner @{tmp}/etilqs_@{hex16} rw,
# Allow to search user files
owner @{HOME}/{,**} r,

View file

@ -78,7 +78,7 @@ profile flatpak-app flags=(attach_disconnected,mediate_deleted) {
/var/lib/flatpak/app/{,**} r,
/var/lib/flatpak/exports/** rw,
/var/tmp/etilqs_@{hex} rw,
/var/tmp/etilqs_@{hex16} rw,
@{run}/.userns r,
@{run}/parent/** r,

View file

@ -65,7 +65,7 @@ profile fwupd @{exec_path} flags=(complain,attach_disconnected) {
/var/lib/flatpak/exports/share/mime/mime.cache r,
/var/lib/fwupd/{,**} rw,
/var/lib/fwupd/pending.db rwk,
/var/tmp/etilqs_@{hex} rw,
/var/tmp/etilqs_@{hex16} rw,
/boot/{,**} r,
/boot/EFI/*/.goutputstream-@{rand6} rw,

View file

@ -31,16 +31,16 @@ profile gpo @{exec_path} {
@{bin}/less rPx -> child-pager,
@{bin}/more rPx -> child-pager,
owner @{PROC}/@{pid}/fd/ r,
/etc/inputrc r,
/usr/share/gpodder/extensions/{,*.py} r,
owner @{HOME}/gPodder/ rw,
owner @{HOME}/gPodder/** rwk,
/usr/share/gpodder/extensions/{,*.py} r,
owner /var/tmp/etilqs_@{hex16} rw,
/etc/inputrc r,
owner /var/tmp/etilqs_@{hex} rw,
owner @{PROC}/@{pid}/fd/ r,
include if exists <local/gpo>
}

View file

@ -39,8 +39,8 @@ profile protonmail-bridge-core @{exec_path} {
owner "@{user_config_dirs}/autostart/Proton Mail Bridge.desktop" rw,
owner @{tmp}/bridge@{int} rw,
owner @{tmp}/user/@{uid}/etilqs_@{hex} rw,
owner /var/tmp/etilqs_@{hex} rw,
owner @{tmp}/etilqs_@{hex16} rw,
owner /var/tmp/etilqs_@{hex16} rw,
@{PROC}/ r,
@{PROC}/sys/net/core/somaxconn r,

View file

@ -56,7 +56,7 @@ profile psi @{exec_path} {
owner @{user_share_dirs}/psi/** rwk,
owner @{tmp}/#@{int} rw,
owner @{tmp}/etilqs_@{hex} rw,
owner @{tmp}/etilqs_@{hex16} rw,
owner @{tmp}/Psi.* rwl -> /tmp/#@{int},
@{run}/systemd/inhibit/[0-9]*.ref rw,

View file

@ -56,7 +56,7 @@ profile psi-plus @{exec_path} {
owner @{user_share_dirs}/psi+/** rwk,
owner @{tmp}/#@{int} rw,
owner @{tmp}/etilqs_@{hex} rw,
owner @{tmp}/etilqs_@{hex16} rw,
owner @{tmp}/Psi+.* rwl -> /tmp/#@{int},
@{run}/systemd/inhibit/[0-9]*.ref rw,

View file

@ -63,7 +63,7 @@ profile quiterss @{exec_path} {
owner @{tmp}/qtsingleapp-quiter-@{int}-@{int} rw,
owner @{tmp}/qtsingleapp-quiter-@{int}-@{int}-lockfile rwk,
owner /var/tmp/etilqs_@{hex} rw,
owner /var/tmp/etilqs_@{hex16} rw,
# Allowed apps to open
@{lib}/firefox/firefox rPUx,

View file

@ -64,7 +64,7 @@ profile strawberry @{exec_path} {
owner @{tmp}/.*/s rw,
owner @{tmp}/*= w,
owner @{tmp}/#@{int} rw,
owner @{tmp}/etilqs_@{hex} rw,
owner @{tmp}/etilqs_@{hex16} rw,
owner @{tmp}/qipc_{systemsem,sharedmemory}_*[a-f0-9]* rw,
owner @{tmp}/strawberry-cover-@{rand6}.jpg rwl -> @{tmp}/#@{int},
owner @{tmp}/strawberry*[0-9] w,