mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2024-11-14 23:43:56 +01:00
feat(profile): add ddcutil
This commit is contained in:
parent
41b1489b76
commit
cb4f3af58e
@ -39,6 +39,7 @@ profile systemd-udevd @{exec_path} flags=(attach_disconnected,complain) {
|
|||||||
@{coreutils_path} rix,
|
@{coreutils_path} rix,
|
||||||
@{bin}/*-print-pci-ids rix,
|
@{bin}/*-print-pci-ids rix,
|
||||||
@{bin}/alsactl rPUx,
|
@{bin}/alsactl rPUx,
|
||||||
|
@{bin}/ddcutil rPx,
|
||||||
@{bin}/dmsetup rPUx,
|
@{bin}/dmsetup rPUx,
|
||||||
@{bin}/ethtool rix,
|
@{bin}/ethtool rix,
|
||||||
@{bin}/issue-generator rPx,
|
@{bin}/issue-generator rPx,
|
||||||
|
47
apparmor.d/profiles-a-f/ddcutil
Normal file
47
apparmor.d/profiles-a-f/ddcutil
Normal file
@ -0,0 +1,47 @@
|
|||||||
|
# apparmor.d - Full set of apparmor profiles
|
||||||
|
# Copyright (C) 2024 Alexandre Pujol <alexandre@pujol.io>
|
||||||
|
# SPDX-License-Identifier: GPL-2.0-only
|
||||||
|
|
||||||
|
abi <abi/3.0>,
|
||||||
|
|
||||||
|
include <tunables/global>
|
||||||
|
|
||||||
|
@{exec_path} = @{bin}/ddcutil
|
||||||
|
profile ddcutil @{exec_path} {
|
||||||
|
include <abstractions/base>
|
||||||
|
include <abstractions/consoles>
|
||||||
|
include <abstractions/dri>
|
||||||
|
include <abstractions/nameservice-strict>
|
||||||
|
|
||||||
|
capability sys_admin,
|
||||||
|
|
||||||
|
@{exec_path} mr,
|
||||||
|
|
||||||
|
@{sh_path} rix,
|
||||||
|
@{bin}/find rix,
|
||||||
|
@{bin}/sed rix,
|
||||||
|
@{bin}/xargs rix,
|
||||||
|
@{bin}/grep rix,
|
||||||
|
|
||||||
|
owner @{user_cache_dirs}/ddcutil/ rw,
|
||||||
|
owner @{user_cache_dirs}/ddcutil/** rwlk,
|
||||||
|
|
||||||
|
@{run}/udev/data/* r,
|
||||||
|
|
||||||
|
@{sys}/ r,
|
||||||
|
@{sys}/bus/ r,
|
||||||
|
@{sys}/bus/** r,
|
||||||
|
@{sys}/class/ r,
|
||||||
|
@{sys}/class/** r,
|
||||||
|
@{sys}/devices/ r,
|
||||||
|
@{sys}/devices/** r,
|
||||||
|
|
||||||
|
owner @{PROC}/@{pid}/fd/ r,
|
||||||
|
|
||||||
|
/dev/ r,
|
||||||
|
/dev/i2c-@{int} rwk,
|
||||||
|
|
||||||
|
include if exists <local/ddcutil>
|
||||||
|
}
|
||||||
|
|
||||||
|
# vim:syntax=apparmor
|
@ -84,6 +84,7 @@ cups-notifier-mailto complain
|
|||||||
cups-notifier-rss complain
|
cups-notifier-rss complain
|
||||||
cups-pk-helper-mechanism complain
|
cups-pk-helper-mechanism complain
|
||||||
cupsd attach_disconnected,complain
|
cupsd attach_disconnected,complain
|
||||||
|
ddcutil complain
|
||||||
DiscoverNotifier complain
|
DiscoverNotifier complain
|
||||||
dkms attach_disconnected,complain
|
dkms attach_disconnected,complain
|
||||||
dockerd attach_disconnected,complain
|
dockerd attach_disconnected,complain
|
||||||
|
Loading…
Reference in New Issue
Block a user