Commit graph

814 commits

Author SHA1 Message Date
Alexandre Pujol
f53550525e
feat(profiles): add the X-strict abstraction. 2022-06-09 22:45:14 +01:00
Alexandre Pujol
5d45b8e7a7
feat(profiles): add the dconf-write abstraction. 2022-06-09 21:55:55 +01:00
Alexandre Pujol
583d7a15f0
feat(profiles): add dbus rules for some common profiles. 2022-06-05 23:06:14 +01:00
Alexandre Pujol
e949654614
feat(profiles): dbus abstactions and related rules. 2022-06-05 22:57:29 +01:00
Alexandre Pujol
63e5980d8d
feat(profiles): general update. 2022-06-05 22:47:37 +01:00
Alexandre Pujol
f6b6e99cde
feat(profiles): initial dbus rules for systemd profiles. 2022-06-05 14:53:10 +01:00
nobodysu
a333a77cb5 polishing 2022-06-05 15:36:10 +03:00
nobodysu
2bea426d27 polishing 2022-06-03 23:00:08 +03:00
Alexandre Pujol
a6a72cd5c3
feat(profiles): initial dbus integration (no dbus rule yet). 2022-06-03 20:38:23 +01:00
Alexandre Pujol
aa606bbdc4
feat(profiles): add swtpm_ioctl. 2022-06-03 20:23:28 +01:00
Alexandre Pujol
9ad819a196
feat(profiles): add install-catalog. 2022-06-03 20:22:07 +01:00
Alexandre Pujol
aa9a673fb6
feat(profiles): add anacron. 2022-06-03 20:21:20 +01:00
Alexandre Pujol
24cf14ff3a
feat(profiles): initial version of some ubuntu related profiles. 2022-06-03 20:20:32 +01:00
Alexandre Pujol
b9552c3f66
feat(profiles): add networkd-dispatcher. 2022-06-03 20:17:08 +01:00
Alexandre Pujol
82bbe96bfa
feat(profiles): add ModemManager. 2022-06-03 20:16:38 +01:00
Alexandre Pujol
82e6dc13e9
feat(profiles): add gnome-remote-desktop-daemon. 2022-06-03 20:15:23 +01:00
Alexandre Pujol
5987818b42
feat(profiles): add gnome-control-center-goa-helper. 2022-06-03 20:14:38 +01:00
Alexandre Pujol
c32b19a808
feat(profiles): general update. 2022-06-03 20:13:11 +01:00
Alexandre Pujol
879416b062
feat(profiles): better system nss rules in nameservice-strict. 2022-06-03 19:38:34 +01:00
Alexandre Pujol
d9a0e24e40
revert(profiles): remove deprecated profiles. 2022-06-03 19:06:06 +01:00
nobodysu
8b58289500 more polishing 2022-06-03 17:42:22 +00:00
nobodysu
722ce7f78f logrotate: add shred 2022-06-03 17:42:22 +00:00
nobodysu
4a76a69632 polishing 2022-06-03 17:42:22 +00:00
nobodysu
9dab6b9794 stricter logind 2022-06-03 17:42:22 +00:00
nobodysu
6b4ae79806 up to date version 2022-06-03 17:42:22 +00:00
nobodysu
e547f6c7bd lost somehow 2022-06-03 17:42:22 +00:00
nobodysu
db9bccc42a complain 2022-06-03 17:42:22 +00:00
nobodysu
b42b8c66cc Ubuntu 22.04, first batch and misc 2022-06-03 17:42:22 +00:00
nobodysu
599ed6464c Ubuntu 22.04, second batch 2022-06-02 19:27:15 +03:00
nobodysu
936431411c ubuntu2204 2022-06-02 02:00:16 +03:00
nobodysu
db649628a5
Update htop (#48) 2022-06-01 17:54:31 +00:00
nobodysu
7db753f0c9
Alphanumeric systemd sessions (#47) 2022-06-01 17:54:07 +00:00
nobodysu
b45161a68e
Armbian mmap (#45) 2022-06-01 17:50:27 +00:00
nobodysu
b4f7ed185c
More consoles requirement after sshd introduction (#44)
* consoles requirement after sshd introduction

* one more
2022-06-01 17:50:05 +00:00
nobodysu
e2b7f6594c
disks-read: Armbian / DietPi (#40) 2022-06-01 17:49:07 +00:00
nobodysu
d5f3d7f686 more egl paths 2022-06-01 20:04:20 +03:00
nobodysu
76417058a6 remove obsolete abstraction 2022-06-01 20:02:48 +03:00
nobodysu
8deddc8a2c
sshd: Ubuntu compatibility (#37)
* Ubuntu, allow fallback

* reverting to Ubuntu compatibility only
2022-05-23 22:16:22 +00:00
nobodysu
481b6d621b pids and header 2022-05-23 20:30:46 +03:00
nobodysu
9a48515089
Add pstree (#38) 2022-05-23 16:55:58 +00:00
nobodysu
6c30e362ee
Add consoles abstraction where needed (#36)
* add consoles abstraction where needed

* not now
2022-05-23 16:43:42 +00:00
nobodysu
a3f94f62b1 uuid 2022-05-23 01:47:42 +03:00
nobodysu
b263321c73 Ubuntu compatibility 2022-05-23 01:44:25 +03:00
Alexandre Pujol
d3d9277978
feat(profiles): more integration for ubuntu 22.04 2022-05-21 17:27:28 +01:00
Alexandre Pujol
e28f5a3bb4
feat(profiles): general update. 2022-05-21 17:25:31 +01:00
Alexandre Pujol
3d2197d7f0
feat(profiles): rewrite the system-config-printer profile. 2022-05-21 17:18:05 +01:00
Alexandre Pujol
df8cb3fe91
feat(profiles): add switcheroo-control. 2022-05-21 17:17:14 +01:00
Alexandre Pujol
6058ef7439
feat(profiles): add systemd-vconsole-setup 2022-05-21 17:16:33 +01:00
Alexandre Pujol
21250f5eec
feat(profiles): add needrestart-iucode-scan-versions. 2022-05-21 17:13:03 +01:00
Alexandre Pujol
1d284c03c3
feat(profiles): add spice-vdagent. 2022-05-21 17:11:20 +01:00
Alexandre Pujol
7a1304720e
feat(profiles): add qemu-ga. 2022-05-21 17:10:49 +01:00
Alexandre Pujol
a5b73375a2
feat(profiles): add im-launch 2022-05-21 17:10:14 +01:00
Alexandre Pujol
e46e9cfcf4
feat(profiles): add boltd. 2022-05-21 17:09:12 +01:00
Alexandre Pujol
59ba69a167
feat(profiles): add ubuntu specific profiles. 2022-05-21 17:07:37 +01:00
Alexandre Pujol
4c7ebb3a39
feat(profile): add gnome-extension-ding
When it is installed as a system extension only.
2022-05-21 16:52:59 +01:00
Alexandre Pujol
8b41f7c9c5
feat(profiles): add some ibus related profiles. 2022-05-21 16:51:46 +01:00
Alexandre Pujol
035bb74b29
feat(profiles: add plymouth. 2022-05-21 16:50:22 +01:00
Alexandre Pujol
0dbe0d2790
feat(profiles) add initial support for ubuntu 22.04 2022-05-21 16:49:45 +01:00
Alexandre Pujol
3ac7d41bf5
chore(profiles): needrestart profiles' apt -> m-r. 2022-05-21 16:38:16 +01:00
Alexandre Pujol
5c382d7eb3
feat(profiles): general update. 2022-05-15 22:56:42 +01:00
Alexandre Pujol
0b66933b45
feat(profiles): general update. 2022-05-09 21:51:18 +01:00
Alexandre Pujol
940c9de083
chore: reorganise the freedesktop group. 2022-05-07 13:18:36 +01:00
Alexandre Pujol
da1b3e1f1c
feat(profiles): general update. 2022-05-07 11:42:18 +01:00
Alexandre Pujol
6aadd82293
feat(profiles): add support for distribution that use /usr/libexec. 2022-05-07 11:35:21 +01:00
Alexandre Pujol
7377aed016
fix: remove absraction from upstream. 2022-05-06 21:29:06 +01:00
Alexandre Pujol
c91363a0b6
fix: abstraction gtk -> gtk complete. 2022-05-06 21:28:41 +01:00
Alexandre Pujol
82e53fd919
feat(profiles): add swtpm, swtpm_localca and swtpm_setup. 2022-05-02 18:12:07 +01:00
Alexandre Pujol
3018ce3bbd
feat(profiles): add flatpak-portal. 2022-05-02 18:07:15 +01:00
Alexandre Pujol
c61181b548
feat(profiles): add sshd profile. 2022-05-02 17:56:06 +01:00
Alexandre Pujol
b87f1859cf
refactor(profiles): merge apt & apt-get profiles. 2022-05-02 17:50:47 +01:00
Alexandre Pujol
8353f0f37f
feat(profiles): add needrestart. 2022-05-02 17:49:03 +01:00
Alexandre Pujol
90ae1ad454
feat(profiles): dpkg-status -> needrestart-dpkg-status 2022-05-02 17:34:58 +01:00
Alexandre Pujol
c950c74bf7
feat(profiles): general update. 2022-05-02 17:33:39 +01:00
Alexandre Pujol
f022ca3299
feat: move sys revision into the mesa abstraction. 2022-05-02 17:25:40 +01:00
Mikhail Morfikov
35a281d045
update apparmor profiles
Signed-off-by: Alexandre Pujol <alexandre@pujol.io>
2022-04-26 22:30:01 +01:00
Alexandre Pujol
85e7f58d3c
feat: add molly-guard profile. 2022-04-26 22:06:19 +01:00
Alexandre Pujol
e845a172c2
feat: update profiles. 2022-04-26 22:05:29 +01:00
Alexandre Pujol
84dc85b82d
fix: fix polkit integration. 2022-04-17 23:14:50 +01:00
Alexandre Pujol
0a7860694f
feat: profile update. 2022-04-17 23:13:53 +01:00
Alexandre Pujol
1ad60d3b1c
feat: profiles update. 2022-04-13 22:04:36 +01:00
Alexandre Pujol
ef9c451559
feat: support for gnome 42. 2022-04-13 20:47:28 +01:00
Alexandre Pujol
57df9ee898
feat: xdg-document-portal add flatpack integration. 2022-04-07 21:30:31 +01:00
Alexandre Pujol
87496adbc7
feat: add initial flatpack-system-helper 2022-04-07 21:28:13 +01:00
Alexandre Pujol
2ffa1faa23
feat: add initial version of login. 2022-04-07 21:18:55 +01:00
Alexandre Pujol
4702e8fdd3
feat: add nullmailer-send. 2022-04-07 21:11:21 +01:00
Alexandre Pujol
7479b595e9
feat: add irqbalance. 2022-04-07 21:11:02 +01:00
Alexandre Pujol
c60787b5f3
feat: add initial version of fail2ban. 2022-04-07 21:10:16 +01:00
Alexandre Pujol
3e15dcabc6
feat: add some con related profiles. 2022-04-07 21:08:40 +01:00
Alexandre Pujol
5eb4e1f526
feat: add initial version of atd. 2022-04-07 21:06:24 +01:00
Alexandre Pujol
5cbe2a0ec1
feat: add update-cracklib 2022-04-07 21:03:41 +01:00
Alexandre Pujol
40fdd3da5e
fix: remove irssi and pidgin as they are present in other sources. 2022-04-07 21:02:02 +01:00
Alexandre Pujol
26cb8f6b86
feat: add uptimed. 2022-04-07 21:01:01 +01:00
Alexandre Pujol
53682c678d
feat: add sulogin profile. 2022-04-07 21:00:39 +01:00
Alexandre Pujol
e078fe2767
feat: add etckeeper profile. 2022-04-07 20:58:58 +01:00
Alexandre Pujol
711c7d917c
feat: add agetty profile. 2022-04-07 20:57:32 +01:00
Alexandre Pujol
10cdde9fb7
feat: update profiles. 2022-04-07 20:53:35 +01:00
Alexandre Pujol
6d1fa42f25
feat: update profiles. 2022-03-30 22:20:56 +01:00
Alexandre Pujol
9d40327b00
refactor: simplify the trash abstraction. 2022-03-30 22:15:13 +01:00
Alexandre Pujol
a59387ac9e
Profile update. 2022-03-27 14:25:29 +01:00
Alexandre Pujol
20c3b0575c
General profiles update. 2022-03-26 20:43:47 +00:00
Alexandre Pujol
d7be27411b
Update profiles. 2022-03-23 19:56:11 +00:00
Alexandre Pujol
2cdd954613
Add nvtop. 2022-03-18 16:06:59 +00:00
Alexandre Pujol
ea366754d7
Profiles update. 2022-03-18 16:05:36 +00:00
Alexandre Pujol
4ff371e739
Profiles update. 2022-03-17 14:01:50 +00:00
Alexandre Pujol
bb0847f5df
Profiles update. 2022-03-13 21:04:42 +00:00
beroal
8e34c5968b
Add ssh-keygen (#35) 2022-03-06 14:05:37 +00:00
Alexandre Pujol
e437fe3a57
Add scrcpy. 2022-03-06 14:02:20 +00:00
Alexandre Pujol
8d5e0fc37c
Add glib-compile-resources. 2022-03-06 14:01:14 +00:00
Alexandre Pujol
020b118b46
Add gnome-terminal-server. 2022-03-06 13:58:58 +00:00
Alexandre Pujol
3fd489a442
Add gnome-photos-thumbnailer. 2022-03-06 13:57:08 +00:00
Alexandre Pujol
f9fde0b482
Profiles update. 2022-03-06 13:56:12 +00:00
Alexandre Pujol
a4e8eab6a2
Improve xorg support in Gnome. 2022-03-06 13:54:43 +00:00
Alexandre Pujol
d993caae98
Add user-write completion file. 2022-03-04 21:31:07 +00:00
Alexandre Pujol
1e729e6b46
Profiles update. 2022-03-04 21:30:34 +00:00
Alexandre Pujol
7b09b8c99a
browser: add security key support & re-format the profiles. 2022-03-03 21:22:17 +00:00
Alexandre Pujol
60cb62334b
Profile update. 2022-03-02 18:22:57 +00:00
Alexandre Pujol
683da55bb9
/proc/sys/kernel/random/boot_id is part of nameservice-strict. 2022-03-02 18:19:25 +00:00
Alexandre Pujol
28ee94c4a5
s3fs: rework the profile. 2022-03-02 18:15:33 +00:00
Alexandre Pujol
57dfcc758d
Fix pipewrire & chromium. 2022-02-27 19:11:31 +00:00
Alexandre Pujol
84e2a56eb9
Profiles update. 2022-02-27 12:18:10 +00:00
Alexandre Pujol
64e5f3ec2a
git: restric access to projects dir and format the profile. 2022-02-27 12:10:43 +00:00
Mikhail Morfikov
8713fb514f
remove useless apparmor profiles 2022-02-27 01:25:10 +00:00
Alexandre Pujol
d701e39939
update apparmor profiles
Co-authored-by: Mikhail Morfikov <mmorfikov@gmail.com>
Signed-off-by: Alexandre Pujol <alexandre@pujol.io>
2022-02-27 01:22:35 +00:00
Alexandre Pujol
477d3f28a0
Add downloadhelper profile. 2022-02-22 20:55:27 +00:00
Alexandre Pujol
8b803a6285
Flatpack: add initial integration in other profiles. 2022-02-22 20:53:52 +00:00
Alexandre Pujol
8c2d39c232
Flatpack: add flatpak-session-helper. 2022-02-22 20:52:46 +00:00
Alexandre Pujol
2064783251
Update profiles. 2022-02-22 20:51:28 +00:00
Alexandre Pujol
0ee2e4f7ad
New @{uuid} variable. 2022-02-22 13:14:46 +00:00
Alexandre Pujol
773741c85e
Merge branch 'su_sudo2' of https://github.com/nobodysu/apparmor.d into su_sudo2
su & sudo: Ubuntu compatibility, Debian polishing
2022-02-22 12:52:18 +00:00
nobodysu
53ee5d0c83 update 2022-02-21 21:46:55 +03:00
nobodysu
a3a6a0fa1a update 2022-02-20 02:33:32 +03:00
nobodysu
ceb60bde82 update 2022-02-20 02:29:31 +03:00
nobodysu
b5cdd0af44 update 2022-02-20 02:21:48 +03:00
Alexandre Pujol
501bb66c64
Add locale-gen profile. 2022-02-16 19:21:11 +00:00
Alexandre Pujol
ac39df1af2
Update profiles. 2022-02-16 19:18:14 +00:00
nobodysu
d22aff27ac
Ubuntu compatibility, Debian polishing (#27) 2022-02-16 17:00:38 +00:00
Alexandre Pujol
1143ea4d6d
aa-log: allow reading more log files. 2022-02-16 13:30:31 +00:00
nobodysu
9df0bd07aa su & sudo: Ubuntu compatibility, Debian polishing 2022-02-13 04:32:51 +03:00
Alexandre Pujol
6876938719
aa-log: add -f option to set a log file. 2022-02-10 21:30:51 +00:00
Alexandre Pujol
ba0ccc3edc
Move glib based profiles. 2022-02-09 20:11:28 +00:00
Alexandre Pujol
810985a0cd
Update profile from #25 (2). 2022-02-09 19:35:18 +00:00
Alexandre Pujol
6294159d7a
Update profile from #25. 2022-02-08 19:49:31 +00:00
Alexandre Pujol
9ecc1aa240
Update profiles. 2022-02-08 18:16:45 +00:00
Alexandre Pujol
7274f98fa6
Add s3fs profile. 2022-02-05 20:57:49 +00:00
Alexandre Pujol
10fd4ed8dd
Add aa-enabled profile. 2022-02-05 20:56:38 +00:00
Alexandre Pujol
dc19fc72a8
Update profiles. 2022-02-05 20:02:10 +00:00
Alexandre Pujol
54472e187b
Profiles update. 2022-01-28 13:00:18 +00:00
Alexandre Pujol
fede23bc28
Add evince. 2022-01-23 13:40:11 +00:00
Alex
f892402037
Merge pull request #20 from nobodysu/patch-9
Update pulseaudio
2022-01-23 13:47:05 +01:00
nobodysu
7e04347af9
Update pulseaudio 2022-01-22 21:46:26 +00:00
Alex
1f49f17821
Merge pull request #21 from nobodysu/typos
Typos: `@{run}`
2022-01-22 12:32:17 +01:00
Alex
45bc5b6645
Merge pull request #18 from nobodysu/patch-7
Update acpid
2022-01-22 12:28:06 +01:00
Alex
16096bbd85
Merge pull request #9 from nobodysu/bind-utils
bind-utils: add host and nslookup.
2022-01-22 12:12:24 +01:00
nobodysu
a79fc3f17b
Update pulseaudio 2022-01-19 23:34:35 +00:00
nobodysu
b95ea13bbd typos 2022-01-18 02:45:11 +03:00
nobodysu
ec9a4d3a6c
Update acpid 2022-01-16 23:31:45 +00:00
nobodysu
70d50632bb
Update acpid 2022-01-16 22:28:45 +00:00
nobodysu
39bd0932d2
Update dig 2022-01-16 21:59:28 +00:00
Mikhail Morfikov
76cd5c7029
update apparmor profiles
Signed-off-by: Alexandre Pujol <alexandre@pujol.io>
2022-01-16 20:15:25 +00:00
Alex
697b296298
Merge pull request #13 from nobodysu/grc_ls_ss
ss
2022-01-16 20:41:57 +01:00
nobodysu
0d9fbff993
Update pulseaudio 2022-01-16 00:20:11 +00:00
nobodysu
56f72ee8f9
Update ss 2022-01-16 00:07:33 +00:00
nobodysu
52aa210f70
Delete grc 2022-01-15 23:54:08 +00:00
nobodysu
0cb633ecec
Update acpid 2022-01-15 23:45:52 +00:00
nobodysu
43c509f28b
Update host 2022-01-15 23:22:43 +00:00
nobodysu
ccabf0ad5e
Update nslookup 2022-01-15 23:14:32 +00:00
Alex
d7ad51d41e
Merge pull request #16 from nobodysu/patch-8
nameservice-strict: Ubuntu compatibility
2022-01-15 19:36:27 +01:00
Alex
3f09ba5ed4
Merge pull request #15 from nobodysu/patch-6
Update dfc
2022-01-15 19:34:17 +01:00
Alex
c1acae8ec2
Merge pull request #14 from nobodysu/patch-5
Update nmap
2022-01-15 19:29:31 +01:00
Alexandre Pujol
8627618d8c
mount: support for squashfs. 2022-01-15 17:36:41 +00:00
Alexandre Pujol
1970e14b46
Pulseaudio: fix dconf access.
Fix #19.
2022-01-15 17:31:48 +00:00
nobodysu
d6148c7b23
Update grc
- `mount` is too much, for now
- expanding `ro` paths
2022-01-10 21:49:01 +00:00
nobodysu
80bd1028c5
Update acpid
Another case. Tested on Debian 11 and Ubuntu LTS.
2022-01-10 21:29:53 +00:00
Alexandre Pujol
065dad53e3
Add tailscale profiles. 2022-01-09 20:24:35 +01:00
Alexandre Pujol
2e7b6f8ba8
Update profiles. 2022-01-09 20:23:18 +01:00
nobodysu
5c1a1f6f8e
Update acpid 2021-12-24 00:00:41 +00:00
nobodysu
777f46779f
Typo? 2021-12-21 10:39:12 +00:00
nobodysu
b9b844c182
Ubuntu compatibility 2021-12-21 10:20:45 +00:00
nobodysu
0fce337239
Update grc 2021-12-20 15:54:20 +00:00
nobodysu
864e09e539
Remove vim header 2021-12-18 21:51:01 +00:00
nobodysu
85b83a6e40
Remove vim header 2021-12-18 21:50:40 +00:00
nobodysu
b6e4b4b743 fixes 2021-12-19 00:40:26 +03:00
nobodysu
83f7132fe1
Update dfc
Ubuntu noise
2021-12-18 18:36:07 +00:00
nobodysu
5be4256404
Update nmap
Ubuntu support, iflist, unprivileged
2021-12-18 15:53:53 +00:00
Alexandre Pujol
accf5538bd
Merge branch 'nobodysu'
* nobodysu:
  Update su
2021-12-14 18:33:20 +00:00
nobodysu
3101d9e7b6 grc, ls , ss 2021-12-14 01:07:50 +03:00
nobodysu
56f598824c
Update ssh 2021-12-13 19:07:16 +00:00
nobodysu
c55f19c4eb bind-utils 2021-12-12 21:42:24 +03:00
nobodysu
09fdd074f8
Update su 2021-12-12 18:16:30 +00:00
Mikhail Morfikov
3430e3df90
update apparmor profiles
Signed-off-by: Alexandre Pujol <alexandre@pujol.io>
2021-12-12 13:18:41 +00:00
Alexandre Pujol
44aca3ba51
Profiles update. 2021-12-12 12:41:50 +00:00
Alexandre Pujol
16dddf16dc
Add sysctl profile. 2021-12-12 12:36:17 +00:00
Alexandre Pujol
0dcd8832f3
Remove untested torbrowser. 2021-12-09 12:38:09 +00:00
Alexandre Pujol
dec82f5eb3
Add aurpublish profile. 2021-12-08 17:41:41 +00:00
Alexandre Pujol
11e0066432
Add askpass profile. 2021-12-08 17:39:21 +00:00
Alexandre Pujol
dc0347388b
Update profiles. 2021-12-08 17:38:43 +00:00
Alexandre Pujol
ad754b26c6
Add xdg-desktop-portal-gnome. 2021-12-05 19:19:44 +00:00
Alexandre Pujol
1644b70d6d
Rethink the configure process. 2021-12-05 00:13:11 +00:00
Alexandre Pujol
0fc9c8b5b0
Add Github Action & add support for the last Ubuntu LTS. 2021-12-05 00:13:00 +00:00
Alexandre Pujol
b52cbe564c
Disks: support large number of disks.
Fix: #4
See: https://github.com/torvalds/linux/blob/master/Documentation/admin-guide/devices.txt
2021-12-01 13:38:14 +00:00
Alexandre Pujol
ddc9fdef45
Merge branch 'qemu_virtual_drives' of https://github.com/nobodysu/apparmor.d into nobodysu-qemu_virtual_drives
* 'qemu_virtual_drives' of https://github.com/nobodysu/apparmor.d:
  QEMU guest virtual disks compatibility
2021-12-01 13:20:18 +00:00
nobodysu
7336b914cb
Update spectre-meltdown-checker
- since this script is not from a package it should, optionally, reside in `local` PATH
- allow to confine it with original name and without renaming
- use marco instead of repeating the path
2021-12-01 01:38:51 +00:00
nobodysu
0f50672486 QEMU guest virtual disks compatibility 2021-12-01 02:18:38 +03:00
nobodysu
27be52f9ae
Update spectre-meltdown-checker 2021-11-30 23:00:14 +00:00
nobodysu
44bcd2a394
Update spectre-meltdown-checker 2021-11-30 21:00:16 +00:00
nobodysu
5059946c4f
Update spectre-meltdown-checker 2021-11-30 17:47:40 +00:00
Alexandre Pujol
1cdd38ea40
Add archlinux-java profile. 2021-11-20 14:14:05 +00:00
Alexandre Pujol
079100e67a
Update profiles. 2021-11-20 14:13:45 +00:00
Alexandre Pujol
0fe5be032f
Add wireplumber. 2021-11-15 00:05:28 +00:00
Alexandre Pujol
f05635015f
Add power-profiles-daemon. 2021-11-15 00:04:35 +00:00
Alexandre Pujol
ac2386957b
Rewrite aa-log. 2021-11-09 22:41:12 +00:00
Alexandre Pujol
2cc4d69e9e
Update profiles. 2021-11-09 21:49:16 +00:00
Alexandre Pujol
5eeccc84f8
Add cert-sync profile. 2021-11-04 18:35:24 +00:00
Alexandre Pujol
3b4af3c89e
Add mono-sgen profile. 2021-11-04 18:34:37 +00:00
Alexandre Pujol
477df29dd5
Update profiles. 2021-11-04 18:33:25 +00:00
Alexandre Pujol
27fe14152b
Add dconf profile. 2021-11-04 18:29:07 +00:00
Alexandre Pujol
7da59b4984
update apparmor profiles 2021-10-22 15:41:13 +01:00
Alexandre Pujol
6c34573727
Add pkttyagent. 2021-10-22 15:02:10 +01:00
Alexandre Pujol
aac0a93080
Profiles update. 2021-10-22 15:01:43 +01:00
Alexandre Pujol
b91ddfa493
Add initial systemd-portabled. 2021-10-22 14:55:22 +01:00
Alexandre Pujol
2fc59385a6
Add initial systemd-oomd. 2021-10-22 14:54:40 +01:00
Alexandre Pujol
b659edf8ae
Add systemd-user-sessions. 2021-10-07 15:01:55 +01:00
Alexandre Pujol
ba0706a2d2
Add systemd-user-runtime-dir. 2021-10-07 15:01:40 +01:00
Alexandre Pujol
0d5d65b0af
Add systemd-update-utmp. 2021-10-07 15:01:13 +01:00
Alexandre Pujol
6890fff556
Add systemd-update-done. 2021-10-07 15:00:55 +01:00
Alexandre Pujol
966e4f7f00
Add systemd-sleep. 2021-10-07 15:00:29 +01:00
Alexandre Pujol
a2dc5b1132
Add initial cockpit profiles. 2021-10-07 14:58:54 +01:00
Alexandre Pujol
1a31d8271e
Add xdg-desktop-portal. 2021-10-07 14:56:01 +01:00
Alexandre Pujol
be82c4cde8
Add xdg-document-portal. 2021-10-07 14:55:40 +01:00
Alexandre Pujol
0d3b2bb4b2
Add xdg-permission-store. 2021-10-07 14:55:22 +01:00
Alexandre Pujol
45e3a280f4
Add resolvconf. 2021-10-07 14:54:48 +01:00
Alexandre Pujol
7a1c462a5e
pass-extension-python -> pass-import. 2021-10-07 14:53:28 +01:00
Alexandre Pujol
2fc138a4d7
/run -> @{run}, [0-9]* -> @{uid}. 2021-10-07 14:52:41 +01:00
Alexandre Pujol
9c8c2144b8
Profiles update. 2021-10-07 14:50:46 +01:00
Alexandre Pujol
66d02dab2b
Add gssproxy. 2021-09-28 21:59:28 +01:00
Alexandre Pujol
6bd8e64c78
Add dpkg-status. 2021-09-28 21:58:25 +01:00
Alexandre Pujol
162670237c
Add unattended-upgrade profiles. 2021-09-28 21:58:12 +01:00
Alexandre Pujol
c6ab1770d0
Libvirtd: update abstractions. 2021-09-28 21:57:52 +01:00
Alexandre Pujol
c4f1e00fba
Add apparmor.systemd. 2021-09-28 21:57:25 +01:00
Alexandre Pujol
e0434f22a4
Modernise the man profile. 2021-09-28 21:57:07 +01:00
Alexandre Pujol
adabcd6b94
Move libvirtd profiles. 2021-09-28 21:54:57 +01:00
Alexandre Pujol
b79ffa52c6
Update profiles. 2021-09-28 21:53:50 +01:00
Alexandre Pujol
8334473902
Add password-store profiles. 2021-09-26 18:16:21 +01:00
Alexandre Pujol
cc16ceb246
distribution -> usr. 2021-09-26 18:12:30 +01:00
Alexandre Pujol
4b288b3eb4
Add aa-log. 2021-09-26 17:30:24 +01:00
Alexandre Pujol
f4d8830963
Add slirp4netns 2021-09-26 17:30:06 +01:00
Alexandre Pujol
a6f1a58743
Add spice-client-glib-usb-acl-helper. 2021-09-26 17:29:46 +01:00
Alexandre Pujol
2b4aa5580f
Add new{u,g}idmap 2021-09-26 17:29:28 +01:00
Alexandre Pujol
cb94385ed7
Add fuse-overlayfs 2021-09-26 17:29:07 +01:00
Alexandre Pujol
18e4745fb1
Profiles update. 2021-09-26 17:28:26 +01:00
Alexandre Pujol
723695c626
Update profiles. 2021-09-19 20:37:32 +01:00
Alexandre Pujol
1956680160
Add userdbctl. 2021-09-15 20:44:40 +01:00
Alexandre Pujol
204ff035e7
Add firecfg. 2021-09-15 20:43:17 +01:00
Alexandre Pujol
1eead1e773
Add apparmor_parser. 2021-09-15 20:42:26 +01:00
Alexandre Pujol
d90aecaa40
Add systemd-cg* profiles 2021-09-15 20:41:44 +01:00
Alexandre Pujol
79ab7e3eec
Update profiles. 2021-09-15 20:40:47 +01:00
Alexandre Pujol
d95a876424
Add two profiles directory to have smaller dir. 2021-09-15 16:55:27 +01:00
Alexandre Pujol
6c0ae4ddc1
child-lsb_release -> lsb_release. 2021-09-15 16:30:28 +01:00
Mikhail Morfikov
2a6b2bd189
update apparmor profiles 2021-09-15 16:16:01 +01:00
Alexandre Pujol
efda369670
Add libvirt profiles. 2021-09-12 20:48:41 +01:00
Alexandre Pujol
fda83bbba7
Add containerd profile. 2021-09-12 20:47:36 +01:00
Alexandre Pujol
a4ba26133f
Update profiles. 2021-09-12 20:47:14 +01:00
Alexandre Pujol
70b4fa665b
Profiles update. 2021-09-10 00:17:44 +01:00
Alexandre Pujol
6583a7bfb2
Update profiles. 2021-09-04 13:59:45 +01:00
Alexandre Pujol
ca4be147f8
Fix video abstraction. 2021-08-22 15:43:53 +01:00
Alexandre Pujol
3c1a201e4a
Initial pacman profiles. 2021-08-22 15:38:14 +01:00
Alexandre Pujol
020eb0daf6
Add mkinitcpio. 2021-08-22 15:35:27 +01:00
Alexandre Pujol
b2d3af8bca
Update profiles. 2021-08-22 15:32:42 +01:00
Alexandre Pujol
f922a5f8e8
BUILD_DIR -> user_build_dirs. 2021-08-22 15:28:23 +01:00
Alexandre Pujol
b65955d055
Better tunables definitions. 2021-08-20 19:14:49 +01:00
Mikhail Morfikov
9eecac80a2
update apparmor profiles 2021-08-20 18:52:56 +01:00
Alexandre Pujol
fb63699153
Add gnome-disks 2021-08-14 13:00:36 +01:00
Alexandre Pujol
fae9d697f6
Add gnome-music. 2021-08-14 13:00:23 +01:00
Alexandre Pujol
6bea2fbd25
Add geoclue profile. 2021-08-14 12:59:43 +01:00
Alexandre Pujol
33f99711a2
Update profiles. 2021-08-14 12:59:24 +01:00
Alexandre Pujol
2d92925882
Profile update. 2021-08-02 11:14:58 +01:00
Alexandre Pujol
4582d6e201
Fix & update flags. 2021-07-31 19:29:39 +01:00
Alexandre Pujol
c7722391c1
Add gnome-control-center. 2021-07-31 19:21:52 +01:00
Alexandre Pujol
4489568b82
Add gnome-tweaks. 2021-07-31 19:17:34 +01:00
Alexandre Pujol
80a1b1b401
Add gnome-system-monitor. 2021-07-31 19:17:25 +01:00
Alexandre Pujol
d38c573844
Add gnome-disk-image-mounter. 2021-07-31 19:16:42 +01:00
Alexandre Pujol
19ada552fe
Profiles update. 2021-07-31 18:41:54 +01:00
Alexandre Pujol
94978242ff
Update profiles. 2021-07-16 21:33:11 +01:00
Alexandre Pujol
aa3c43c999
Add pinentry profiles. 2021-07-11 17:22:08 +01:00
Alexandre Pujol
bba090d727
Add gnome-extensions-app. 2021-07-11 17:20:29 +01:00
Alexandre Pujol
2372188d8e
Update profiles. 2021-07-11 17:20:09 +01:00
Alexandre Pujol
cb6344c64f
Add aa-status. 2021-07-08 19:42:57 +01:00
Alexandre Pujol
9828ae566f
media-keys: add audio abstracion. 2021-07-08 18:16:22 +01:00
Alexandre Pujol
b50c926784
Add zram-generator. 2021-07-08 12:57:00 +01:00
Alexandre Pujol
a0d703a3ee
Add systemd-delta & systemd-path. 2021-07-08 12:54:52 +01:00
Alexandre Pujol
178459f406
Profile update. 2021-07-08 12:53:17 +01:00
Alexandre Pujol
30c414d439
Update profiles. 2021-07-05 19:10:20 +01:00
Alexandre Pujol
ca13b4be36
Add pkcs11-register. 2021-06-29 20:10:39 +01:00
Alexandre Pujol
9cff5676c8
Add start-pulseaudio-x11. 2021-06-29 20:10:07 +01:00
Alexandre Pujol
b3352522ea
Add wl-copy. 2021-06-29 20:09:45 +01:00
Alexandre Pujol
f7e0824826
Add the systemd-tty-ask-password-agent profile. 2021-06-29 20:04:51 +01:00
Alexandre Pujol
a8a1f3b29a
Add virtlogd profile. 2021-06-29 20:03:06 +01:00
Alexandre Pujol
aceb3d7560
Add gtk-query-immodules. 2021-06-29 20:01:26 +01:00
Alexandre Pujol
8bab95223f
Add systemd-mount. 2021-06-29 19:59:25 +01:00
Alexandre Pujol
ab5958c511
Update profiles. 2021-06-29 19:55:56 +01:00
Alexandre Pujol
d084023120
Add update-ca-trust 2021-06-12 15:21:28 +01:00
Alexandre Pujol
6bbe50573b
Update profiles. 2021-06-12 15:21:16 +01:00
Alexandre Pujol
4ee6cc9657
/usr/{lib,libexec} -> @{libexec} 2021-06-06 15:02:40 +01:00
Alexandre Pujol
9ad8ec165d
Profiles update. 2021-06-06 14:55:17 +01:00
Alexandre Pujol
44dc86cd36
Small fixes. 2021-05-30 16:15:29 +01:00
Alexandre Pujol
9b7ab9cbc3
Add paccache profile. 2021-05-26 20:49:04 +01:00
Alexandre Pujol
58978c12b7
Profile update. 2021-05-26 20:44:42 +01:00
Alexandre Pujol
797701d0a0
Pipewire: use tunable vars. 2021-05-26 20:34:41 +01:00
Mikhail Morfikov
e085014238
update apparmor profiles 2021-05-26 20:23:28 +01:00
Alexandre Pujol
420aebcfa5
Small fixes. 2021-05-16 21:11:55 +01:00
Alexandre Pujol
a4fe3209c9
Move debian only profiles. 2021-05-16 21:10:16 +01:00
Alexandre Pujol
717505daf5
Minor corrections. 2021-05-11 22:07:20 +01:00
Alexandre Pujol
dfcafbe472
Move some profiles. 2021-05-11 22:03:28 +01:00
Alexandre Pujol
e6dc08caec
Add some profiles. 2021-05-09 00:34:57 +01:00
Alexandre Pujol
a8d1205e76
Profile update. 2021-05-09 00:33:10 +01:00
Alexandre Pujol
faa3e70c8f
Add some systemd profiles. 2021-05-09 00:31:43 +01:00
Alexandre Pujol
665fd26419
Add some gnome related profiles. 2021-05-08 19:07:45 +01:00
Alexandre Pujol
bfa2293379
Profile update. 2021-05-08 19:06:48 +01:00
Alexandre Pujol
0d566a43b9
Profiles update. 2021-05-06 16:44:49 +01:00
Alexandre Pujol
ae5f781175
Move some profiles. 2021-05-03 19:14:46 +01:00
Alexandre Pujol
f7948962fc
Profiles update. 2021-05-03 12:58:46 +01:00
Alexandre Pujol
86ac65eb5c
Update profiles. 2021-05-01 21:22:23 +01:00
Alexandre Pujol
0c494ed2ba
General profiles update. 2021-04-29 21:02:28 +01:00
Alexandre Pujol
559020861b
Add idbus profiles. 2021-04-29 21:00:25 +01:00
Alexandre Pujol
001c2028f6
Move dbus profiles. 2021-04-29 20:58:31 +01:00
Alexandre Pujol
49bddc0382
Profile update. 2021-04-23 12:40:19 +01:00
Alexandre Pujol
749859920e
Some fixes. 2021-04-21 21:57:17 +01:00
Alexandre Pujol
a49e221949
Add reflector. 2021-04-21 21:56:29 +01:00
Alexandre Pujol
d84c699fbd
arch-audit: add dac_read_search. 2021-04-21 21:56:13 +01:00
Alexandre Pujol
7029d40c5e
systemd: better profilling and rename journalctl. 2021-04-21 21:55:50 +01:00
Alexandre Pujol
1c9df4b3b9
Gnome fixes. 2021-04-21 21:55:01 +01:00
Alexandre Pujol
d929d662f5
Add glib-pacrunner. 2021-04-21 21:54:29 +01:00
Alexandre Pujol
926c89de95
Move some profiles. 2021-04-21 21:53:54 +01:00
Alexandre Pujol
b373c0ec63
borg: allow cat. 2021-04-19 15:28:54 +01:00
Alexandre Pujol
1f11e6398b
Add @{MOUNTS} for all common mountpoints. 2021-04-19 15:20:32 +01:00
Alexandre Pujol
a5ec3e559c
Disk mount fix. 2021-04-19 15:15:38 +01:00
Alexandre Pujol
4a35b7d804
Use @{uid} instead of [0-9]* when it denotes the user id. 2021-04-18 19:00:15 +01:00
Alexandre Pujol
cd4ad5b09c
Minor fixes. 2021-04-18 17:54:04 +01:00
Mikhail Morfikov
5faf590bf5
update apparmor profiles 2021-04-18 17:48:20 +01:00
Alexandre Pujol
f5d1386f74
Add xdg-user-dirs-update 2021-04-16 13:37:26 +01:00
Alexandre Pujol
53b01b1132
Some fixes. 2021-04-16 13:37:15 +01:00
Alexandre Pujol
d41df93da1
Add tracker-extract 2021-04-16 13:36:28 +01:00
Alexandre Pujol
2e5c8f2f72
Add more systemd profiles. 2021-04-15 22:52:14 +01:00
Alexandre Pujol
370dda124d
Various fixes. 2021-04-15 22:51:21 +01:00
Alexandre Pujol
8fdd8a7b21
Add missing gdm term signal. 2021-04-13 15:13:06 +01:00
Alexandre Pujol
7a3ba21d50
Add gdm profiles. 2021-04-13 14:14:23 +01:00
Alexandre Pujol
ea746ad8d7
Minor fixes. 2021-04-13 14:10:50 +01:00
Alexandre Pujol
7be8aca10d
Minor fixes. 2021-04-12 19:59:41 +01:00
Alexandre Pujol
3734e5aedf
Add include if exists abstractions *.d 2021-04-12 19:59:04 +01:00
Alexandre Pujol
8d22bc10b2
Add nautilus profile. 2021-04-12 19:04:42 +01:00
Alexandre Pujol
2175a86979
Profiles update. 2021-04-12 13:33:24 +01:00
Mikhail Morfikov
0573b2d996
update apparmor profiles
Adpated to the apparmor.d structure.

Signed-off-by: Mikhail Morfikov <mmorfikov@gmail.com>
2021-04-10 15:12:56 +01:00
Alexandre Pujol
3d9fc84a41
Profile fixes. 2021-04-10 14:20:23 +01:00
Alexandre Pujol
c04c260cfa
Enforce some profiles. 2021-04-10 14:19:43 +01:00
Alexandre Pujol
89f35e502f
Add gtk 4 support. 2021-04-10 14:18:42 +01:00
Alexandre Pujol
17806e9ee7
Profiles update and general fixes. 2021-04-09 14:47:06 +01:00
Alexandre Pujol
ec9f197842
dbus-daemon: arch & gnome support. 2021-04-08 22:48:40 +01:00
Alexandre Pujol
33296ae19e
Add full gnome shell confinement. 2021-04-08 22:47:42 +01:00
Alexandre Pujol
6bf2a7e826
Update gsd-power. 2021-04-08 22:45:44 +01:00
Alexandre Pujol
87dd65a52d
Add fsck-ext4 2021-04-08 22:44:53 +01:00
Alexandre Pujol
fbc001e786
Add initial auditd. 2021-04-08 22:43:27 +01:00
Alexandre Pujol
ca6006152a
Add initial acpid 2021-04-08 22:42:48 +01:00
Alexandre Pujol
bba7a8e09c
openvpn: network manager support & more classic file strucure. 2021-04-08 22:41:55 +01:00
Alexandre Pujol
a789d518b2
Fix openvpn integration with network manager. 2021-04-08 22:41:05 +01:00
Alexandre Pujol
604a95119d
Add usbguard-notifier. 2021-04-08 22:40:03 +01:00
Alexandre Pujol
731dbe9d70
Add xbrlapi. 2021-04-08 22:39:41 +01:00
Alexandre Pujol
4d883c82d6
Add aa-notify 2021-04-08 22:32:39 +01:00
Alexandre Pujol
29253d0888
Fix licence id. 2021-04-08 22:28:37 +01:00
Alexandre Pujol
81b6f2d960
ps: environ is needed. 2021-04-08 22:26:12 +01:00
Alexandre Pujol
0b171d1330
Cleanup some new profiles. 2021-04-08 22:25:48 +01:00
Alexandre Pujol
91c7069ee1
Abstractions: more definitions. 2021-04-08 22:24:00 +01:00
Alexandre Pujol
04f2d2c9a3
Rules fix. 2021-04-07 18:05:15 +01:00
Alexandre Pujol
9446af57f8
Cleanup. 2021-04-07 18:04:10 +01:00
Alexandre Pujol
550c3957de
Profiles update. 2021-04-06 12:42:47 +01:00
Alexandre Pujol
64d8379375
Global profile update. 2021-04-05 13:15:52 +01:00
Alexandre Pujol
6aa99d3ec5
chromium **needs** dconf. 2021-04-04 22:03:18 +01:00
Alexandre Pujol
f3a982fdf6
Add xdg-dbus-proxy. 2021-04-04 21:28:39 +01:00
Alexandre Pujol
9f17f48c6e
xwayland: small fixes. 2021-04-04 21:28:20 +01:00
Alexandre Pujol
a48b6eed2e
Add gitstatusd & test git. 2021-04-04 20:05:07 +01:00
Alexandre Pujol
d68e8cdf97
Header cosmetic. 2021-04-04 17:37:09 +01:00
Alexandre Pujol
db2501b517
Add Xwayland. 2021-04-04 17:33:35 +01:00
Alexandre Pujol
d570ff123e
Add arch-audit & pacdiff. 2021-04-04 17:28:12 +01:00
Alexandre Pujol
5353729d73
Add pacman-{conf,key} profiles. 2021-04-04 17:27:14 +01:00
Alexandre Pujol
131ef331f5
Update gnome-keyring-daemon. 2021-04-04 17:25:31 +01:00
Alexandre Pujol
62c7e77ffd
Add gnome-shell-calendar-server. 2021-04-04 17:24:53 +01:00
Alexandre Pujol
adf48a2052
Add seahorse profile. 2021-04-04 17:24:44 +01:00
Alexandre Pujol
441f3f776f
Add browserpass profile. 2021-04-04 17:23:53 +01:00
Mikhail Morfikov
046443a702
Update apparmor profiles
Adpated to the apparmor.d structure.

Signed-off-by: Mikhail Morfikov <mmorfikov@gmail.com>
2021-04-04 14:43:10 +01:00
Alexandre Pujol
19521569ce
Complete ss_cert abstraction. 2021-04-04 01:13:25 +01:00
Alexandre Pujol
d38c781bbd
Apparmor Parser issue fix. 2021-04-04 00:46:12 +01:00
Alexandre Pujol
547076dda3
systemd: update related profiles. 2021-04-04 00:37:27 +01:00
Alexandre Pujol
b2c0ead2de
nm: access to all net interfaces. 2021-04-04 00:35:41 +01:00
Alexandre Pujol
f1e3574e2e
media-keys: access to sound settings. 2021-04-04 00:34:54 +01:00
Alexandre Pujol
ec2e1fc1c2
Add mkinitcpio support. 2021-04-04 00:34:05 +01:00
Alexandre Pujol
a0d634b48f
usermod: nscd is required. 2021-04-04 00:01:13 +01:00
Alexandre Pujol
61038bdfa8
Sudo needs much more cap for normal usage. 2021-04-03 23:28:16 +01:00
Alexandre Pujol
660921f57c
ssh: better keys & network access. 2021-04-03 23:26:09 +01:00
Alexandre Pujol
093af6982b
Browser: allow browserpass acess. 2021-04-03 23:25:02 +01:00
Alexandre Pujol
a15061700b
chromium: for now, no access to mozilla files. 2021-04-03 23:24:28 +01:00
Alexandre Pujol
8c935281fd
Evolution: allow access to osrelease & kernel cmd.
Is it really needed?
2021-04-03 23:23:03 +01:00