.. |
apparmor_api
|
Make @{sys} available by default
|
2018-10-09 19:27:55 +03:00 |
ubuntu-browsers.d
|
Use @{sys} tunable in profiles and abstractions
|
2018-11-08 20:04:46 +02:00 |
apache2-common
|
Add profile names to all profiles with {bin,sbin} attachment
|
2018-10-15 20:57:33 +02:00 |
aspell
|
profiles: allow aspell access to /usr/share/aspell/
|
2015-02-27 23:14:03 -08:00 |
audio
|
Fix local pulseaudio config file access
|
2017-12-17 15:56:21 +02:00 |
authentication
|
Make policy compatible with merged-/usr.
|
2016-12-03 10:59:01 +01:00 |
base
|
Use @{sys} tunable in profiles and abstractions
|
2018-11-08 20:04:46 +02:00 |
bash
|
Subject: profiles - use @{pid} tunable
|
2013-01-02 15:34:38 -08:00 |
consoles
|
as ACKed on IRC, drop the unused $Id$ tags everywhere
|
2010-12-20 12:29:10 -08:00 |
cups-client
|
profiles: rw file perms are now needed on AF_UNIX socket files
|
2013-12-19 23:19:40 -08:00 |
dbus
|
profiles: Add strict system bus abstraction
|
2014-01-10 15:34:45 -06:00 |
dbus-accessibility
|
profiles: Add strict accessibility bus abstraction
|
2014-01-10 15:35:30 -06:00 |
dbus-accessibility-strict
|
profiles: Add strict accessibility bus abstraction
|
2014-01-10 15:35:30 -06:00 |
dbus-session
|
profiles: Add strict session bus abstraction
|
2014-01-10 15:35:09 -06:00 |
dbus-session-strict
|
profiles/apparmor.d/abstractions/X: make x11 socket read-only
|
2018-12-08 13:52:03 +01:00 |
dbus-strict
|
profiles: Add strict system bus abstraction
|
2014-01-10 15:34:45 -06:00 |
dconf
|
dconf abstraction: allow reading /etc/dconf/**.
|
2015-07-19 15:42:54 +02:00 |
dovecot-common
|
Add profile names to all profiles with {bin,sbin} attachment
|
2018-10-15 20:57:33 +02:00 |
dri-common
|
Move DRI-specific rules into it's own abstraction
|
2018-02-04 14:21:16 +02:00 |
dri-enumerate
|
Use @{sys} tunable in profiles and abstractions
|
2018-11-08 20:04:46 +02:00 |
enchant
|
Fix from Felix Geyer: in the enchant abstraction, allow the creation of
|
2012-01-10 11:37:54 +01:00 |
fcitx
|
profiles: Create abstractions for fcitx input method framework
|
2016-06-04 00:27:59 -05:00 |
fcitx-strict
|
profiles: Create abstractions for fcitx input method framework
|
2016-06-04 00:27:59 -05:00 |
fonts
|
Updated abstractions to allow writing to some common config dirs
|
2018-08-14 16:38:18 -04:00 |
freedesktop.org
|
Rename @{usr_share} → @{system_share_dirs} and @{home_local_share} → @{user_share_dirs}.
|
2018-07-27 06:33:42 +00:00 |
gnome
|
Updated abstractions to allow creating some common config dirs
|
2018-08-14 16:38:18 -04:00 |
gnupg
|
abstractions/gnupg: allow pubring.kbx
|
2018-01-20 23:54:08 +01:00 |
ibus
|
add preliminary ibus abstraction. Will likely need more once more ibus users
|
2010-12-22 16:57:35 -06:00 |
kde
|
Include qt5 into kde abstraction
|
2018-09-30 13:03:59 +03:00 |
kde-globals-write
|
Add kde-globals-write abstraction
|
2018-08-14 16:49:07 -07:00 |
kde-icon-cache-write
|
Add kde-icon-cache-write abstraction
|
2018-08-14 16:49:30 -07:00 |
kde-language-write
|
Add kde-language-write abstraction
|
2018-08-14 16:49:16 -07:00 |
kerberosclient
|
Update samba profiles for samba 4.x
|
2013-11-20 01:17:52 +01:00 |
ldapclient
|
ldapclient abstraction: allow rw access to the nslcd socket.
|
2018-07-30 22:49:24 -04:00 |
libpam-systemd
|
usr.sbin.sshd: refresh profile and add libpam-systemd abstractions
|
2016-01-08 20:43:56 -05:00 |
likewise
|
as ACKed on IRC, drop the unused $Id$ tags everywhere
|
2010-12-20 12:29:10 -08:00 |
mdns
|
update for /var/run -> /run udev transition. For compatibility, distributions
|
2011-07-14 07:57:57 -05:00 |
mesa
|
mesa abstraction: allow locking .cache/mesa_shader_cache/??/*.
|
2018-07-24 07:21:51 +00:00 |
mir
|
profiles: add mir abstraction
|
2015-03-05 11:46:11 -08:00 |
mozc
|
profiles: Create abstraction for mozc input method editor
|
2016-06-04 00:28:03 -05:00 |
mysql
|
abstractions/mysql: allow access to mysqld.sock
|
2014-04-28 14:07:17 -07:00 |
nameservice
|
Allow reading /etc/netconfig in abstractions/nameservice
|
2017-10-20 22:53:09 +02:00 |
nis
|
as ACKed on IRC, drop the unused $Id$ tags everywhere
|
2010-12-20 12:29:10 -08:00 |
nvidia
|
Use @{sys} tunable in profiles and abstractions
|
2018-11-08 20:04:46 +02:00 |
opencl
|
Add OpenCL abstractions
|
2018-05-13 20:14:15 +00:00 |
opencl-common
|
Use @{sys} tunable in profiles and abstractions
|
2018-11-08 20:04:46 +02:00 |
opencl-intel
|
Use @{sys} tunable in profiles and abstractions
|
2018-11-08 20:04:46 +02:00 |
opencl-mesa
|
Add OpenCL abstractions
|
2018-05-13 20:14:15 +00:00 |
opencl-nvidia
|
Use @{sys} tunable in profiles and abstractions
|
2018-11-08 20:04:46 +02:00 |
opencl-pocl
|
Use @{sys} tunable in profiles and abstractions
|
2018-11-08 20:04:46 +02:00 |
openssl
|
add FIPS support to abstractions/openssl
|
2014-01-03 20:43:43 +01:00 |
orbit2
|
fixes for abstractions from Mathias Gug
|
2007-08-28 23:05:56 +00:00 |
p11-kit
|
profiles: rw file perms are now needed on AF_UNIX socket files
|
2013-12-19 23:19:40 -08:00 |
perl
|
Author: Jamie Strandboge <jamie@canonical.com>
|
2017-06-26 14:04:52 -05:00 |
php
|
abstractions/php: allow ICU (unicode support) data tables
|
2018-09-02 15:46:43 +02:00 |
php5
|
Add backwards compatibility php5 abstraction
|
2016-12-07 02:46:59 -08:00 |
postfix-common
|
postifx-common: Allow access to dynamicmaps, most seems to use it
|
2018-11-30 14:23:56 +01:00 |
private-files
|
deny ~/.mutt** in private-files and audit deny ~/.aws in private-files-strict
|
2018-11-19 16:13:57 -06:00 |
private-files-strict
|
deny ~/.mutt** in private-files and audit deny ~/.aws in private-files-strict
|
2018-11-19 16:13:57 -06:00 |
python
|
abstractions/python: allow /usr/local/lib/python3
|
2018-08-15 15:06:10 +02:00 |
qt5
|
Add qt5-compose-cache-write abstraction
|
2018-08-15 13:25:19 +03:00 |
qt5-compose-cache-write
|
qt5-compose-cache-write: fix anonymous shared memory access
|
2019-01-12 12:34:22 +02:00 |
qt5-settings-write
|
Add qt5-write abstraction
|
2018-08-15 13:02:21 +03:00 |
recent-documents-write
|
Add recent-documents-write abstraction
|
2018-08-07 23:27:23 +03:00 |
ruby
|
abstractions/ruby: add /usr/local/ and vendor_ruby paths
|
2014-09-08 21:36:47 +02:00 |
samba
|
Update usr.sbin.nmbd & usr.sbin.smbd
|
2018-10-02 11:58:57 +03:00 |
smbpass
|
as ACKed on IRC, drop the unused $Id$ tags everywhere
|
2010-12-20 12:29:10 -08:00 |
ssl_certs
|
abstractions/ssl_{certs,keys}: allow reading ocsp.der maintained by dehydrated for OCSP stapling
|
2019-01-03 08:31:06 -05:00 |
ssl_keys
|
abstractions/ssl_{certs,keys}: sort the alternation for dehydrated and drop the "-" from the filenames
|
2019-01-03 08:29:21 -05:00 |
svn-repositories
|
as ACKed on IRC, drop the unused $Id$ tags everywhere
|
2010-12-20 12:29:10 -08:00 |
ubuntu-bittorrent-clients
|
profiles: Add deluge-{gtk,console} to ubuntu-bittorrent-clients abstraction
|
2016-03-19 03:08:52 -05:00 |
ubuntu-browsers
|
Fix ubuntu-browsers for 64bit openSUSE
|
2018-04-01 16:48:13 +03:00 |
ubuntu-console-browsers
|
don't #include ubuntu-helpers in the abstractions. This can only be included
|
2012-01-11 09:00:35 +01:00 |
ubuntu-console-email
|
don't #include ubuntu-helpers in the abstractions. This can only be included
|
2012-01-11 09:00:35 +01:00 |
ubuntu-email
|
ubuntu-email: allow running Thunderbird wrapper script
|
2018-09-27 21:04:32 +03:00 |
ubuntu-feed-readers
|
don't #include ubuntu-helpers in the abstractions. This can only be included
|
2012-01-11 09:00:35 +01:00 |
ubuntu-gnome-terminal
|
update ubuntu abstractions to use '# vim:syntax=apparmor'
|
2010-12-21 12:53:33 -06:00 |
ubuntu-helpers
|
profiles: support distributions which merge sbin into bin
|
2018-07-25 14:07:35 -07:00 |
ubuntu-konsole
|
Subject: profiles - use @{pid} tunable
|
2013-01-02 15:34:38 -08:00 |
ubuntu-media-players
|
don't #include ubuntu-helpers in the abstractions. This can only be included
|
2012-01-11 09:00:35 +01:00 |
ubuntu-unity7-base
|
profiles/apparmor.d/abstractions/ubuntu-unity7-base: update to use dbus
|
2016-03-10 16:53:24 -06:00 |
ubuntu-unity7-launcher
|
add ubuntu-unity7-* abstractions for Ubuntu desktop users
|
2014-02-05 23:44:04 -05:00 |
ubuntu-unity7-messaging
|
add ubuntu-unity7-* abstractions for Ubuntu desktop users
|
2014-02-05 23:44:04 -05:00 |
ubuntu-xterm
|
update for /var/run -> /run udev transition. For compatibility, distributions
|
2011-07-14 07:57:57 -05:00 |
user-download
|
fix user_download abstraction for non-latin file names
|
2017-06-24 18:12:22 +03:00 |
user-mail
|
abstractions/user-mail: /var/mail/* should only be accessible to their owners
|
2016-04-14 15:15:36 -04:00 |
user-manpages
|
From: Christian Boltz <apparmor@cboltz.de>
|
2011-08-05 13:12:35 -07:00 |
user-tmp
|
as ACKed on IRC, drop the unused $Id$ tags everywhere
|
2010-12-20 12:29:10 -08:00 |
user-write
|
fix user-write abstraction for non-latin file names
|
2017-07-02 12:22:21 +03:00 |
video
|
Use @{sys} tunable in profiles and abstractions
|
2018-11-08 20:04:46 +02:00 |
vulkan
|
Use @{sys} tunable in profiles and abstractions
|
2018-11-08 20:04:46 +02:00 |
wayland
|
profiles/apparmor.d/abstractions/X: make x11 socket read-only
|
2018-12-08 13:52:03 +01:00 |
web-data
|
Add /var/www/html to abstractions/web-data, which is the path used on Debian
|
2014-02-27 14:49:54 -06:00 |
winbind
|
update abstractions/winbind
|
2014-02-14 23:37:13 +01:00 |
wutmp
|
Merge k permission for /var/log/lastlog into abstractions/wutmp
|
2011-08-16 12:26:44 +02:00 |
X
|
profiles/apparmor.d/abstractions/X: make x11 socket read-only
|
2018-12-08 13:52:03 +01:00 |
xad
|
as ACKed on IRC, drop the unused $Id$ tags everywhere
|
2010-12-20 12:29:10 -08:00 |
xdg-desktop
|
Create an xdg-desktop abstraction based on the upstream documentation for
|
2012-01-11 13:00:34 +01:00 |