Alexandre Pujol
5fdbc2d00e
fix(profiles): minor bug fixes.
2022-10-18 19:20:12 +01:00
nobody43
81fd594be2
Update apparmor.d/profiles-g-l/htop
...
Co-authored-by: Alex <roddhjav@users.noreply.github.com>
2022-10-17 15:09:52 +00:00
nobodysu
8d61d3256a
more profiles
2022-10-17 17:07:26 +03:00
nobodysu
349689cba4
polishing2
2022-10-16 17:46:39 +03:00
nobodysu
41659f073c
polishing
2022-10-16 17:45:00 +03:00
nobodysu
c6ca84ded4
remove spaces
2022-10-16 17:20:49 +03:00
nobodysu
f637c70f99
remove complain
2022-10-16 17:17:53 +03:00
nobodysu
ac7c42eefd
New user login
2022-10-16 17:12:23 +03:00
Alexandre Pujol
c15f2fbb7b
feat(profiles): ensure ibus-daemon integration with Ubuntu.
2022-10-16 12:15:12 +01:00
Alexandre Pujol
e7fbf5fbef
feat(profiles): better ubuntu integration.
2022-10-15 18:03:23 +01:00
Alexandre Pujol
2aa4618dda
feat(profiles): gnome-session-binary ensure compatibility across distribution.
2022-10-15 17:32:01 +01:00
nobodysu
643a84997e
Unbreak Debian 11 and partially Ubuntu 22.04 (Wayland+GDM+Gnome) ( #81 )
...
* Unbreaking Debian 11 and partially Ubuntu 22.04
* pre-cleanup
* pre-cleanup2
* Update im-launch
* Update gnome-extension-ding
* polishing
* not yet
* Update ubuntu.flags
Allow GDM to boot. `No new privs` fix.
* Update debian.flags
Allow GDM to boot. `No new privs` fix.
* Update CONTRIBUTING.md
* fixes
* reverting w
* move setpriv to main.flags
2022-10-14 21:21:56 +00:00
Alexandre Pujol
bdcaa040fe
feat(profiles): add packagekitd.
2022-10-14 22:18:49 +01:00
Alexandre Pujol
b1950cbe91
feat(profiles): general update.
2022-10-14 22:17:27 +01:00
Alexandre Pujol
3c841e6d6a
fix(profiles): ensure all firefox start is cached.
2022-10-14 22:13:23 +01:00
Alexandre Pujol
513abeb59d
refactor: move child profiles into children group.
2022-10-14 22:12:46 +01:00
Alexandre Pujol
eddf6bfc4f
feat(profiles): general update.
2022-10-08 13:13:44 +01:00
Alexandre Pujol
e226f4eb03
feat(profiles): add iwd.
2022-10-06 21:13:05 +01:00
Alexandre Pujol
736e44a483
feat(profiles): general update.
2022-10-06 20:53:54 +01:00
Alexandre Pujol
ddedb39f3d
refactor: move profile in correct group.
2022-10-06 20:51:30 +01:00
Alexandre Pujol
e4e54a26ef
feat(profiles): restrict path access in pacman.
2022-10-06 20:50:41 +01:00
Alexandre Pujol
ece6524886
fix(profile): fix gio-launch-desktop attachments.
2022-10-06 20:48:08 +01:00
Alexandre Pujol
418107f11e
feat(profiles): allow gvfs-metadata on some profile that really need it.
2022-10-06 20:47:22 +01:00
Alexandre Pujol
1c97feb5c2
feat(profiles): add modprobed-db.
2022-10-06 20:45:31 +01:00
Alexandre Pujol
c2952b1ec5
feat(profiles): more flexibility in password-store dir name.
2022-10-06 20:43:39 +01:00
Alexandre Pujol
ac47e292ac
feat(profiles): general update.
2022-10-04 21:11:13 +01:00
Alexandre Pujol
d0a8030af8
fix(profile): add deny-sensitive-home abstraction.
2022-10-01 19:18:54 +01:00
Alexandre Pujol
8a55eb8330
fix(profile): fontconfig-cache-write needs /var/cache/fontconfig/ access.
2022-10-01 19:11:19 +01:00
Alexandre Pujol
f45c07dfa1
feat(profiles): child-open integration 2/2
2022-10-01 19:10:00 +01:00
Alexandre Pujol
b29f9675eb
feat(profiles): browser - add child-open integration & cleanup.
2022-10-01 19:08:15 +01:00
Alexandre Pujol
7d3c52036b
feat(profiles): add child-open.
2022-10-01 19:05:44 +01:00
Alexandre Pujol
e7d73243af
refactor: move child-systemctl the children group.
2022-10-01 19:04:35 +01:00
Alexandre Pujol
39740f9369
feat(profiles): add systemd-dissect.
2022-10-01 18:56:02 +01:00
Alexandre Pujol
1a73271a1a
feat(profiles): add localectl.
2022-10-01 18:53:11 +01:00
Alexandre Pujol
65bf8278bc
feat(profiles): add gnome-browser-connector-host.
2022-10-01 18:47:49 +01:00
Alexandre Pujol
7c3fcf260c
feat(profiles): add systemd-id128.
2022-10-01 18:46:32 +01:00
Alexandre Pujol
4681a495b3
feat(profiles): general update.
2022-10-01 18:45:08 +01:00
Alexandre Pujol
5580a34184
refactor: move chrome-gnome-shell to the gnome group.
2022-10-01 18:38:29 +01:00
Alexandre Pujol
768e50c6ab
fix: remove not modified lxc rules.
...
Fix #79
2022-09-28 11:54:29 +01:00
Alexandre Pujol
9f2b68dd5d
feat(profiles): add ubuntu-advantage-desktop-daemon.
2022-09-26 14:59:54 +01:00
Alexandre Pujol
205c2d7184
feat(profiles): new children group.
...
This group is reserved for profile without an attachment path because
it is ended to be used only via "Px -> <profile-name>".
2022-09-26 14:59:18 +01:00
Alexandre Pujol
42f305b244
feat(profiles): add XDG_GAMES_DIR and user_games_dirs variables.
2022-09-24 18:23:11 +01:00
Alexandre Pujol
060ea3acc9
feat(profiles): add archlinux-keyring-wkd-sync.
2022-09-24 18:21:56 +01:00
Alexandre Pujol
8ff571549a
feat(profiles): add gnome-extension-manager.
2022-09-24 18:09:05 +01:00
Alexandre Pujol
a02e67d980
feat(profiles): askpass -> code-askpass.
2022-09-24 18:08:00 +01:00
Alexandre Pujol
f2989321eb
feat(profiles): general update.
2022-09-24 18:06:06 +01:00
Alexandre Pujol
ae6cecde52
feat(profiles): deny gvfs-metadata when possible.
2022-09-24 17:59:20 +01:00
beroal
fcee586e9e
viewing DjVu and PostScript files ( #78 )
2022-09-24 11:13:21 +00:00
Alexandre Pujol
a432d656c8
feat(profiles): add sbctl.
2022-09-18 11:21:33 +01:00
Alexandre Pujol
4920922394
feat(profiles): add busctl.
2022-09-13 18:39:41 +01:00
Alexandre Pujol
3c7dda5060
feat(profiles): allow most dbus access to gnome.
2022-09-13 18:17:11 +01:00
Alexandre Pujol
58e060c470
Merge branch 'master' of github.com:roddhjav/apparmor.d
...
* 'master' of github.com:roddhjav/apparmor.d:
bulk cross-OS awk (#75 )
2022-09-11 20:48:03 +01:00
Alexandre Pujol
80a8be6d9e
feat(profiles): move some flags definition in main.flags
2022-09-11 20:47:49 +01:00
Alexandre Pujol
8ff5ed7a69
feat(profiles): general update.
2022-09-11 20:45:14 +01:00
nobodysu
78a180b2f6
bulk cross-OS awk ( #75 )
2022-09-11 19:40:34 +00:00
nobodysu
8fb8e7ced3
lost abi
2022-09-06 22:03:19 +01:00
nobodysu
912a6c48e5
cleanup2
2022-09-06 22:03:19 +01:00
nobodysu
7720802dac
cleanup
2022-09-06 22:03:19 +01:00
nobodysu
cd646ea899
broader gdm
2022-09-06 22:03:19 +01:00
nobodysu
71a7c25a6d
Delete lightdm-guest-session
2022-09-06 22:02:21 +01:00
nobodysu
fe59b4d3f8
Delete lightdm_chromium-browser
2022-09-06 22:02:21 +01:00
nobodysu
f02ec5d273
Delete lightdm
2022-09-06 22:02:21 +01:00
Jeroen
9818daba5f
LVM and general update ( #68 )
...
* Small fixes
* General update
* Add LVM
* Various small fixes
* Add profile
* Typo
* sbin to regex
* Date and time to extends
* Read cmdline
* Remove grep duplicate
* Small fixes
* Typo
* Permissions for warning scripts
* Add net_admin for multipath
2022-09-06 21:01:17 +00:00
nobodysu
1649b427f8
Ubuntu 22.04, third batch ( #65 )
...
* initial
* ready
* cleanup
* cleanup2
* Update dbus-gtk
2022-09-06 17:00:18 +00:00
Alexandre Pujol
70aea89ad4
Revert "fix: the trash abstraction has been upstreamed."
...
This reverts commit 688a62e9bc
.
Fix #71
2022-09-06 17:52:08 +01:00
Alexandre Pujol
746a36bfb4
feat(profiles): add our virt-aa-helper.
2022-09-03 16:10:17 +01:00
Alexandre Pujol
769627fc25
feat(profiles): remove libvirt abstractions.
2022-09-03 16:06:31 +01:00
Alexandre Pujol
892d44cca2
feat(profiles): remove unused abstractions.
2022-09-03 16:05:37 +01:00
Alexandre Pujol
688a62e9bc
fix: the trash abstraction has been upstreamed.
2022-09-03 16:04:53 +01:00
Alexandre Pujol
3b56d3ff0f
feat(profiles): use the new hex variable.
2022-09-03 14:43:34 +01:00
Alexandre Pujol
5d0c521e44
feat(profiles): move aurpublish profile.
2022-09-03 14:29:07 +01:00
Alexandre Pujol
14fd88aa2f
feat(profiles): add profiles for cups.
2022-08-31 22:10:41 +01:00
Alexandre Pujol
30f0b69a67
feat(profiles): add losetup profile.
2022-08-31 21:58:55 +01:00
Alexandre Pujol
0f61c4649c
feat(profiles): general update.
2022-08-31 21:54:33 +01:00
Alexandre Pujol
0238adaaf1
Merge branch 'ubuntu2204__2' of https://github.com/nobodysu/apparmor.d into nobodysu-ubuntu2204__2
...
* 'ubuntu2204__2' of https://github.com/nobodysu/apparmor.d :
Update pkexec
Update polkitd
update
polishing
polishing
Ubuntu 22.04, second batch
2022-08-22 22:10:46 +01:00
nobodysu
bea1aab15a
Update pkexec
2022-08-21 21:24:20 +00:00
nobodysu
43a366cca3
Update polkitd
2022-08-21 21:23:05 +00:00
Alexandre Pujol
9d4956df0d
feat(profiles): general update.
2022-08-21 20:16:29 +01:00
Alexandre Pujol
e1e7d611ed
fix(profiles): ensure pinentry can start. See #66 .
2022-08-20 13:45:42 +01:00
Alexandre Pujol
79860f207d
feat(profiles): initial support for dockerd.
2022-08-19 21:26:17 +01:00
Alexandre Pujol
e6c91fdfd7
feat(profiles): general update.
2022-08-19 21:10:10 +01:00
Jeroen Rijken
af603fbc62
Revert "tty and pts are part of abstractions/consoles"
...
This reverts commit 51a33f3f5e
.
2022-08-19 19:25:22 +01:00
Jeroen Rijken
35087ea4bb
Add missing brackets
2022-08-19 19:25:22 +01:00
Jeroen Rijken
d538d2a718
Add write to block
2022-08-19 19:25:22 +01:00
Jeroen Rijken
be2a66afff
read all block devices
2022-08-19 19:25:22 +01:00
Jeroen Rijken
c680dfe7db
sort rules
2022-08-19 19:25:22 +01:00
Jeroen Rijken
e64011c4de
zed temp file
2022-08-19 19:25:22 +01:00
Jeroen Rijken
3c634e8967
Create sanoid under run
2022-08-19 19:25:22 +01:00
Jeroen Rijken
f5634b2803
Move update-grub to grub
2022-08-19 19:25:22 +01:00
Jeroen Rijken
5c6bf4c91b
Remove duplicate consoles
2022-08-19 19:25:22 +01:00
Jeroen Rijken
75a66e573e
Use openssl abstraction
2022-08-19 19:25:22 +01:00
Jeroen Rijken
af0c622b35
Replace rm with mr.
2022-08-19 19:25:22 +01:00
Jeroen
e62465b72f
Use multiarch for lib
...
Co-authored-by: Alex <roddhjav@users.noreply.github.com>
2022-08-19 19:25:22 +01:00
Jeroen Rijken
20f7e01ccc
Brackets
2022-08-19 19:25:22 +01:00
Jeroen Rijken
7621dc9974
Fix typo's
2022-08-19 19:25:22 +01:00
Jeroen Rijken
689f48b217
motd fixes
2022-08-19 19:25:22 +01:00
Jeroen Rijken
cf63b97c9b
Add avahi
2022-08-19 19:25:22 +01:00
Jeroen Rijken
099a97cb36
General update
2022-08-19 19:25:22 +01:00
Jeroen Rijken
575d781c88
Various ZFS fixes
2022-08-19 19:25:22 +01:00
Jeroen Rijken
005dec1a53
tty and pts are part of abstractions/consoles
2022-08-19 19:25:22 +01:00
Jeroen Rijken
7ee9644325
Add profiles for whoami, whereis, which, findmnt, users, sanoid and syncoid.
2022-08-19 19:25:22 +01:00
Jeroen Rijken
6af5c76fb8
Add and update CNI profiles
2022-08-19 19:25:22 +01:00
Jeroen Rijken
b1112e35a7
Add templates for all grub commands
2022-08-19 19:25:22 +01:00
Jeroen Rijken
169a730d3f
Add profiles for grub-mkconfig, grub-mkrelpath, grub-probe, grub-script-check and update-grub.
2022-08-19 19:25:22 +01:00
Alexandre Pujol
c0356e92e5
feat(aa-log): add support dbus session log using journactl.
2022-08-19 19:05:46 +01:00
nobodysu
e65a78972b
Merge branch 'master' into ubuntu2204__2
2022-08-18 15:36:21 +00:00
nobodysu
355d958e26
update
2022-08-18 18:22:56 +03:00
Alexandre Pujol
a2fa2421cb
feat(profiles): add the @{hex} variables.
2022-08-13 20:44:59 +01:00
Alexandre Pujol
66b529497d
feat(profiles): initial support for steam & steam games.
2022-08-13 20:36:52 +01:00
Alexandre Pujol
3e331bd656
fix(profiles): @{PROC}/@{uid} -> @{PROC}/@{pid}
2022-08-13 20:33:58 +01:00
Alexandre Pujol
c148aa978c
feat(profiles): general update.
2022-08-13 20:31:57 +01:00
Jeroen Rijken
e02b12aa6d
Add libexec for apt
2022-08-13 15:21:35 +01:00
Jeroen Rijken
cd93d98bf4
Add support for adding snapshots to grub.
2022-08-13 15:21:35 +01:00
Jeroen Rijken
30cbac1181
Fix typo
2022-08-13 15:21:35 +01:00
Jeroen Rijken
5646c90d4c
Fix zsysd profile name
2022-08-13 15:21:35 +01:00
Jeroen Rijken
b6b510aa36
Remove entries duplicate with base abstractions.
2022-08-13 15:21:35 +01:00
Jeroen Rijken
ddf5f1f512
Use nameservice-strict, fix exec
2022-08-13 15:21:35 +01:00
Jeroen Rijken
e2e14510ff
Small fixes
2022-08-13 15:21:35 +01:00
Jeroen Rijken
2affbf6734
Cosmetic fixes
2022-08-13 15:21:35 +01:00
Jeroen Rijken
03881d5614
Add capability, dbus and some proc
2022-08-13 15:21:35 +01:00
Jeroen Rijken
a9fd0706d1
Move complain flag
2022-08-13 15:21:35 +01:00
Jeroen Rijken
d083e927a4
Initial support for zsys
2022-08-13 15:21:35 +01:00
nobodysu
33ff1abc35
Update thunderbird
2022-08-12 14:41:58 +00:00
nobodysu
db8e881c06
Merge branch 'master' into thunderbird2
2022-08-12 14:35:53 +00:00
nobodysu
00a1e70720
polishing
2022-08-12 17:23:13 +03:00
nobodysu
f2394963d0
cleanup
2022-08-08 02:39:35 +03:00
nobodysu
2c2f6e5557
rearrangement
2022-08-02 19:31:00 +03:00
nobodysu
af49797425
cleanup
2022-08-02 01:59:54 +03:00
nobodysu
c96b6d8ee7
dbus-gtk
2022-08-02 01:47:47 +03:00
Alexandre Pujol
2878fa6a2e
feat(profiles): general update.
2022-07-29 16:47:09 +01:00
Jeroen Rijken
58cfe9ad37
Small fixes
2022-07-29 16:41:19 +01:00
Jeroen Rijken
616753aea0
Consolidate rules
2022-07-29 16:41:19 +01:00
Jeroen Rijken
fcea04c69b
Remove complain flags
2022-07-29 16:41:19 +01:00
Jeroen Rijken
e724d835ed
Add ps to ptrace
2022-07-29 16:41:19 +01:00
Jeroen Rijken
e4d118365a
Add Kubernetes pause container
2022-07-29 16:41:19 +01:00
Jeroen Rijken
e6525e1f04
Add missing volumes
2022-07-29 16:41:19 +01:00
Jeroen Rijken
07f1db2725
Fix some typo's
2022-07-29 16:41:19 +01:00
Jeroen Rijken
465a31c638
General updates
2022-07-29 16:41:19 +01:00
Jeroen Rijken
33da7af6e8
container updates
2022-07-29 16:41:19 +01:00
Jeroen Rijken
3af11c4d16
ZFS updates
2022-07-29 16:41:19 +01:00
Alexandre Pujol
7aca29b244
feat(profiles): initial snap support.
2022-07-21 22:40:06 +01:00
Alexandre Pujol
177d27d94c
feat(profiles): general update.
2022-07-21 22:37:17 +01:00
Alexandre Pujol
58b96a7ba9
feat(profiles): add aptd profile.
2022-07-21 22:31:59 +01:00
Alexandre Pujol
595a27560f
feat(profiles): add mullvad profiles.
2022-07-21 20:17:03 +01:00
Alexandre Pujol
48c023d4bd
feat(profiles): containerd support for docker & cosmetic.
2022-07-21 20:15:02 +01:00
Jeroen Rijken
55bd85796c
packagekitd dbus updates
2022-07-21 20:05:56 +01:00
Jeroen Rijken
137433ce6e
dbus to NetworkManager
2022-07-21 20:05:56 +01:00
Jeroen Rijken
eb87e035b8
Initial containerd-shim-runc support
2022-07-21 20:05:56 +01:00
Jeroen Rijken
266d5c6dc0
Add IPV6
2022-07-21 19:46:45 +01:00
Jeroen Rijken
b404d7e4c4
Move xtables-nft to separate profile
2022-07-21 19:46:45 +01:00