feat(profiles): small profiles update.

This commit is contained in:
Alexandre Pujol 2023-03-29 23:55:43 +01:00
parent f3d4912be8
commit cbc1d8faf3
Failed to generate hash of commit
8 changed files with 23 additions and 8 deletions

View file

@ -86,10 +86,11 @@ profile gjs-console @{exec_path} flags=(attach_disconnected) {
/usr/share/icu/{,**} r,
/usr/share/X11/xkb/** r,
/var/lib/gdm{3,}/greeter-dconf-defaults r,
/var/lib/gdm{3,}/.config/dconf/user r,
/var/lib/gdm{3,}/.cache/fontconfig/[a-f0-9]*.cache-?{,.NEW,.LCK,.TMP-*} r,
/var/lib/gdm{3,}/.cache/gstreamer-1.0/ rw,
/var/lib/gdm{3,}/.cache/gstreamer-1.0/registry.*.bin{,.tmp*} rw,
/var/lib/gdm{3,}/.config/dconf/user r,
/var/lib/gdm{3,}/greeter-dconf-defaults r,
/tmp/ r,
/var/tmp/ r,

View file

@ -45,6 +45,9 @@ profile gpg @{exec_path} {
owner /var/lib/*/.gnupg/ rw,
owner /var/lib/*/.gnupg/** rwkl -> /var/lib/*/.gnupg/**,
owner /tmp/ostree-gpg-*/ r,
owner /tmp/ostree-gpg-*/** rwkl -> /tmp/ostree-gpg-*/**,
owner /tmp/tmp.[a-zA-Z0-9]* rw,
owner @{PROC}/@{pid}/fd/ r,

View file

@ -21,6 +21,11 @@ profile grub-mkrelpath @{exec_path} {
/ r,
/usr/share/grub/* r,
/boot/grub/themes/{,**} r,
/tmp/grub-btrfs.*/@snapshots/[0-9]*/snapshot/boot/ r,
/tmp/grub-btrfs.*/ r,
@{PROC}/@{pids}/mountinfo r,
include if exists <local/grub-mkrelpath>

View file

@ -25,6 +25,8 @@ profile grub-probe @{exec_path} {
/ r,
/usr/share/grub/* r,
/boot/grub/themes/{,**} r,
@{PROC}/@{pids}/mountinfo r,
@{PROC}/devices r,

View file

@ -7,7 +7,7 @@ abi <abi/3.0>,
include <tunables/global>
@{exec_path} = /opt/Mullvad*/mullvad-gui
profile mullvad-gui @{exec_path} {
profile mullvad-gui @{exec_path} flags=(attach_disconnected) {
include <abstractions/base>
include <abstractions/chromium-common>
include <abstractions/dconf-write>
@ -52,9 +52,12 @@ profile mullvad-gui @{exec_path} {
owner "/tmp/.org.chromium.Chromium.*/Mullvad VPN*.png" rw,
owner @{run}/user/@{uid}/.mutter-Xwaylandauth.[a-zA-z0-9]* r,
@{run}/systemd/inhibit/*.ref rw,
@{sys}/bus/pci/devices/ r,
@{sys}/devices/virtual/tty/tty[0-9]*/active r,
@{sys}/devices/pci[0-9]*/**/{vendor,device,class,config,resource,irq} r,
@{sys}/devices/system/cpu/** r,
@{sys}/devices/virtual/tty/tty[0-9]*/active r,
@{PROC}/ r,
@{PROC}/sys/fs/inotify/max_user_watches r,

View file

@ -48,6 +48,7 @@ profile containerd-shim-runc-v2 @{exec_path} flags=(attach_disconnected) {
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
@{PROC}/@{pids}/cgroup r,
@{PROC}/@{pids}/mountinfo r,
@{PROC}/@{pids}/oom_score_adj rw,
@{PROC}/sys/net/core/somaxconn r,

View file

@ -23,7 +23,7 @@ profile augenrules @{exec_path} {
/{usr/,}bin/mktemp rix,
/{usr/,}bin/rm rix,
/etc/audit/audit.rules r,
/etc/audit/audit.rules rw,
/etc/audit/rules.d/ r,
owner /tmp/aurules.* rw,

View file

@ -52,9 +52,9 @@ profile os-prober @{exec_path} flags=(attach_disconnected) {
@{MOUNTS}/ r,
/ r,
/boot/ r,
/boot/EFI/ r,
/boot/EFI/*/ r,
/boot/{efi/,} r,
/boot/{efi/,}EFI/ r,
/boot/{efi/,}EFI/*/ r,
owner /tmp/os-prober.*/{,**} rw,