Jamie Strandboge
58f5df11e6
deny writes to upstart user sessions jobs in abstractions/private-files
...
Acked-By: Jamie Strandboge <jamie@canonical.com>
Acked-by: Steve Beattie <sbeattie@ubuntu.com>
2013-05-13 14:56:10 -05:00
Christian Boltz
77f37e84eb
Update abstractios for KDE4
...
(At least) openSUSE uses ~/.kde4 to store KDE4 settings.
This patch changes ~/.kde/ to ~/.kde{,4} in all abstractions.
The patch is mostly from Velery Valery, I only fixed a merge conflict
and added the kmail{,2} part in private-files-strict.
References: https://bugzilla.novell.com/show_bug.cgi?id=741592
Acked-By: Steve Beattie <sbeattie@ubuntu.com> for both trunk and 2.7.
2012-01-19 15:20:28 +01:00
Steve Beattie
25f800ac7d
Fix from Felix Geyer: block write access to ~/.kde/env because KDE
...
automatically sources scripts in that folder on startup.
Bug: https://launchpad.net/bugs/914190
2012-01-10 11:54:12 +01:00
Jamie Strandboge
0cb4e48344
Description: Disallow writing and linking to @{HOME}/.pki/nssdb/ .so files
...
Bug-Ubuntu: https://launchpad.net/bugs/911847
Acked-by: Jamie Strandboge <jamie@canonical.com>
Acked-By: Steve Beattie <sbeattie@ubuntu.com>
2012-01-06 10:29:32 -06:00
Jamie Strandboge
780ae4663d
profiles/apparmor.d/abstractions/private-files:
...
- add zsh files (LP: #761217 )
- add .inputrc (bash)
- add .login and .logout (csh, tcsh, etc)
2011-04-18 08:55:50 -05:00
Jamie Strandboge
f7c6a848bb
abstractions/private-files: don't allow wl to autostart directories
...
abstractions/private-files-strict: don't allow access to:
- chromium
- thunderbird
- evolution
- kmail
- kwallet
2011-01-07 10:44:47 -06:00
Kees Cook
40e8c9f6e6
merge profiles from Ubuntu, including change_hat apache2 template
2009-11-11 11:42:30 -08:00