feat(profile): add new userns rule.

This commit is contained in:
Alexandre Pujol 2024-02-28 15:39:18 +00:00
parent 175d243c54
commit d187514fd3
No known key found for this signature in database
GPG Key ID: C5469996F0DF68EC
6 changed files with 12 additions and 1 deletions

View File

@ -29,6 +29,8 @@ profile discord @{exec_path} {
include <abstractions/thumbnails-cache-read>
include <abstractions/chromium-common>
# userns,
signal (send) set=(kill, term) peer=@{profile_name}//lsb_release,
# Needed for Game Activity

View File

@ -25,6 +25,8 @@ profile plasmashell @{exec_path} flags=(mediate_deleted) {
include <abstractions/recent-documents-write>
include <abstractions/thumbnails-cache-read>
# userns,
network inet dgram,
network inet6 dgram,
network inet stream,

View File

@ -14,6 +14,8 @@ profile systemd-coredump @{exec_path} flags=(attach_disconnected,mediate_deleted
include <abstractions/openssl>
include <abstractions/systemd-common>
# userns,
capability dac_override,
capability dac_read_search,
capability net_admin,

View File

@ -18,6 +18,8 @@ profile element-desktop @{exec_path} {
include <abstractions/ssl_certs>
include <abstractions/video>
# userns,
capability sys_ptrace,
network inet dgram,

View File

@ -17,7 +17,8 @@ profile flatpak @{exec_path} flags=(attach_disconnected,mediate_deleted,complain
include <abstractions/nameservice-strict>
include <abstractions/openssl>
include <abstractions/ssl_certs>
include <abstractions/X-strict>
# userns,
capability dac_override,
capability dac_read_search,

View File

@ -20,6 +20,8 @@ profile steam @{exec_path} flags=(attach_disconnected,mediate_deleted,complain)
include <abstractions/nameservice-strict>
include <abstractions/ssl_certs>
# userns,
capability sys_ptrace,
network inet dgram,