Commit Graph

2866 Commits

Author SHA1 Message Date
Alexandre Pujol
bf2025db09
feat(profile): gpg: ensure compatibility with torbrowser profile from upstream.
see #407
2024-09-01 22:09:00 +01:00
odomingao
52d2cd63b9
Create cemu (#459) 2024-09-01 21:03:13 +00:00
odomingao
7c560e1e8f
Update chronyd (#458)
apparmor="DENIED" operation="create" class="net" profile="chronyd"  comm="chronyd" family="inet" sock_type="stream" protocol=0 requested_mask="create" denied_mask="create"
2024-09-01 21:01:19 +00:00
Alexandre Pujol
b223e2eb8e
feat(profile): general update. 2024-09-01 20:36:23 +01:00
Alexandre Pujol
265e3928c1
feat(profile): mesa: mesa_shader_cache_db is often passed as fd. 2024-09-01 20:13:51 +01:00
Alexandre Pujol
7e3c546e3d
fix(profile): xdg-mime mimetype path.
fix #455
2024-09-01 15:25:43 +01:00
Alexandre Pujol
60e00f8c53
fix(profile): zramctl doesn't show algorithm, data, compression, total, streams, mountpoint
fix #456
2024-09-01 15:22:05 +01:00
Alexandre Pujol
aa4f4de6dd
feat(abs): update mesa shader cache paths.
fix: #450 #451
2024-09-01 15:17:43 +01:00
Alexandre Pujol
fb29e8ba74
doc: general update. 2024-08-30 20:38:30 +01:00
Nishit Majithia
fe32720765
socat: add apparmor profile (#454)
* socat: add apparmor profile

Signed-off-by: Nishit Majithia <nishit.nm@gmail.com>

* socat: update profile

 - Follow profile guideline
 - Change copyright texts
 - Update to use abi 3.0
 - Use `ssl_certs` and `console` abstractions instead of explicit rules

Signed-off-by: Nishit Majithia <nishit.nm@gmail.com>

* socat: minor fix in the profile

 - Use @{bin}
 - Allow executable mapping and read for the binary

Signed-off-by: Nishit Majithia <nishit.nm@gmail.com>

---------

Signed-off-by: Nishit Majithia <nishit.nm@gmail.com>
2024-08-30 16:56:04 +00:00
odomingao
a224adc42e Update xdg-desktop-portal-hyprland 2024-08-30 11:42:38 +00:00
odomingao
75fba4c6c7 Update xdg-desktop-portal 2024-08-30 11:42:38 +00:00
odomingao
21bef5a042 Create xdg-desktop-portal-hyprland 2024-08-30 11:42:38 +00:00
Alexandre Pujol
a1eaf58427
feat(profile): minor update. 2024-08-29 19:05:37 +01:00
Alexandre Pujol
04898e20f9
fix: conflicting x modifiers. 2024-08-28 19:48:01 +01:00
EliasTheGrandMasterOfMistakes
1f83ca358e gnome-shell: Integrate nm-openvpn-auth-dialog on gnome-shell
VPNs that uses gnome authentication like ProtonVPN
depends of gnome-shell acess nm-openvpn-auth-dialog

Co-authored-by: Alexandre Pujol <alexandre@pujol.io>
2024-08-28 18:42:08 +00:00
EricLin0509
7716c8a191 Rewrite the profile for ufw 2024-08-28 18:24:31 +00:00
EricLin0509
d5ee5c51cb Tighten the permissions of ufw 2024-08-28 18:24:31 +00:00
EricLin0509
cecd0a6284 initial support for ufw 2024-08-28 18:24:31 +00:00
valoq
ce26fa103b permit read access 2024-08-28 18:23:44 +00:00
Alexandre Pujol
bb1c4e0537
feat(profile): modernise the crontab profile.
fix #428
2024-08-28 19:19:21 +01:00
Alexandre Pujol
09aef5131e
fix(profile): gpg key generation. 2024-08-28 18:59:51 +01:00
Alexandre Pujol
72d8d14480
feat(tunables): expand coreutils with findutils & diffutils. 2024-08-28 18:53:31 +01:00
Alexandre Pujol
ec7715aaf3
feat(profile): general update. 2024-08-28 18:52:55 +01:00
Alexandre Pujol
c13aa711da
feat(abs): add user bin to the app launch abs. 2024-08-28 18:46:35 +01:00
Alexandre Pujol
f9169bc40b
feat(profile): use the kde-globals-write abstaction when needed. 2024-08-28 18:43:34 +01:00
Alexandre Pujol
1655a9f5ab
feat(profile): more kde integration.
fix #442
2024-08-28 18:30:39 +01:00
odomingao
96d774a9eb Update systemd-journald
apparmor="DENIED" operation="open" class="file" profile="systemd-journald" name="/run/udev/data/+mdio_bus:r8169-0-300:00"  comm="systemd-journal" requested_mask="r" denied_mask="r" fsuid=0 ouid=0 FSUID="root" OUID="root"
2024-08-26 11:01:11 +00:00
Alexandre Pujol
909d3062b5
feat(profile): ssh: add sshd-session
fix #442
2024-08-22 17:43:00 +01:00
valoq
f4330796c4 add write permissions to remove metadata 2024-08-21 10:44:05 +00:00
valoq
c25b76c233 allow read access to atool config files 2024-08-21 10:00:19 +00:00
Alexandre Pujol
6b822d0134
feat(profile): add veracrypt. 2024-08-21 10:26:12 +01:00
Alexandre Pujol
006ed3f681
fix(profile): fscrypt works on a specific homedir.
fix #430
2024-08-21 10:10:28 +01:00
Alexandre Pujol
03639c56bc
fix(profile): add graphics to dino.
See #426
2024-08-21 10:01:36 +01:00
Alexandre Pujol
50831a2fc8
feat(abs): split steam-game abstraction to game and steam-game abstractions. 2024-08-20 21:06:34 +01:00
Alexandre Pujol
788d865939
feat(profile): general update. 2024-08-20 20:56:58 +01:00
Alexandre Pujol
f14ed2f024
feat(profile): rewrite the dino profile.
see #426
2024-08-20 20:13:00 +01:00
Alexandre Pujol
e74fade49a
fix: compilation issue 2/2
revert adding `bin` to XDG_BIN_DIR due to undetected  conflicting x modifiers.

See #424
2024-08-20 19:54:54 +01:00
Alexandre Pujol
fb6e718b98
feat(profile): gdm-session-worker: initial support for fscrypt.
fix #430
2024-08-20 19:29:43 +01:00
Alexandre Pujol
dc8cc1eb09
fix: compilation issue. 2024-08-20 19:09:19 +01:00
Alexandre Pujol
4f4e373877
chore: make go vet happy. 2024-08-20 19:07:56 +01:00
Alexandre Pujol
93313422bd
feat(profile): update kde profiles on openSUSE Tumbleweed.
See #424
2024-08-20 18:49:52 +01:00
Alexandre Pujol
14fae89fdd
fix(profile): modprobed-db access to config files.
fix #435
2024-08-20 17:59:24 +01:00
Alexandre Pujol
fc1ae32e4e
fix(profile): virtlogd: support for user libvirtd.
fix #436
2024-08-20 17:54:34 +01:00
Alexandre Pujol
e3e6c2f5b6
feat(profile): add NTS support for chronyd.
fix #438
2024-08-20 17:51:23 +01:00
Alexandre Pujol
da27a6b27e
fix: mpv needs access to /dev/snd files for the alsa audio backend to work
fix #433
2024-08-20 17:46:46 +01:00
valoq
ad60ee11ad minor improvements 2024-08-06 15:52:04 +00:00
Alexandre Pujol
7d9ae262c9
fix: borg profile mounting issues.
fix 431
2024-08-02 14:54:32 +02:00
Alexandre Pujol
28d5ea034e
feat(profile): merge transmission gui profiles.
Fix conflicting file naming with upstream.

fix #429
2024-07-27 15:15:26 +02:00
Alexandre Pujol
a8509af857
build: update overwrite list from upstream
fix #427
2024-07-27 15:07:20 +02:00