apparmor/profiles/apparmor.d/abstractions
Tyler Hicks 2559b9cfd8 profiles: Add strict accessibility bus abstraction
Create a new strict accessibility bus abstraction.

The strict abstraction only allows for calling the Hello, AddMatch,
RemoveMatch, GetNameOwner, NameHasOwner, and StartServiceByName methods
that are exported by the D-Bus daemon.

The permissive abstraction reuses the strict abstraction and then allows
all communications on the accessibility bus.

Signed-off-by: Tyler Hicks <tyhicks@canonical.com>
Acked-by: John Johansen <john.johansen@canonical.com>
2014-01-10 15:35:30 -06:00
..
apparmor_api Subject: profiles - fix apparmor_api abstractions 2013-01-02 15:02:29 -08:00
ubuntu-browsers.d add Dolphin (default Kubuntu file manager) to the list of file managers in 2013-07-01 17:48:58 +02:00
apache2-common Subject: profiles - use @{pid} tunable 2013-01-02 15:34:38 -08:00
aspell Bug: https://bugs.launchpad.net/bugs/917859 2012-01-18 10:15:57 -08:00
audio update pulseaudio directory and cookie file paths 2013-04-08 20:10:36 -05:00
authentication add p11-kit to authentication abstraction 2012-01-06 11:46:52 -06:00
base add read access to @{PROC}/sys/vm/overcommit_memory as used by glibc. See 2013-04-08 20:11:43 -05:00
bash Subject: profiles - use @{pid} tunable 2013-01-02 15:34:38 -08:00
consoles as ACKed on IRC, drop the unused $Id$ tags everywhere 2010-12-20 12:29:10 -08:00
cups-client profiles: rw file perms are now needed on AF_UNIX socket files 2013-12-19 23:19:40 -08:00
dbus profiles: Add strict system bus abstraction 2014-01-10 15:34:45 -06:00
dbus-accessibility profiles: Add strict accessibility bus abstraction 2014-01-10 15:35:30 -06:00
dbus-accessibility-strict profiles: Add strict accessibility bus abstraction 2014-01-10 15:35:30 -06:00
dbus-session profiles: Add strict session bus abstraction 2014-01-10 15:35:09 -06:00
dbus-session-strict profiles: Add strict session bus abstraction 2014-01-10 15:35:09 -06:00
dbus-strict profiles: Add strict system bus abstraction 2014-01-10 15:34:45 -06:00
dconf Add dconf abstraction for querying dconf settings 2013-10-09 06:18:09 -07:00
enchant Fix from Felix Geyer: in the enchant abstraction, allow the creation of 2012-01-10 11:37:54 +01:00
fonts On Ubuntu saucy fontconfig reads user configs from 2013-10-14 17:38:48 -07:00
freedesktop.org abstractions/freedesktop.org updates: 2010-12-23 18:39:28 -06:00
gnome move poppler cMap from gnome to fonts, thanks to Felix Geyer 2013-05-30 12:01:27 -07:00
gnupg Subject: profiles - owner usage for @{HOME} rules 2013-01-04 22:05:53 -08:00
ibus add preliminary ibus abstraction. Will likely need more once more ibus users 2010-12-22 16:57:35 -06:00
kde Subject: profiles - owner usage for @{HOME} rules 2013-01-04 22:05:53 -08:00
kerberosclient Update samba profiles for samba 4.x 2013-11-20 01:17:52 +01:00
launchpad-integration fix up comments in launchpad-integration 2012-01-11 09:27:22 +01:00
ldapclient split off abstractions/ldapclient from abstractions/nameservice 2011-11-01 17:08:37 +01:00
likewise as ACKed on IRC, drop the unused $Id$ tags everywhere 2010-12-20 12:29:10 -08:00
mdns update for /var/run -> /run udev transition. For compatibility, distributions 2011-07-14 07:57:57 -05:00
mysql abstractions/mysql: changed paths and MariaDB support 2013-01-13 14:38:28 +01:00
nameservice Subject: profiles - use @{pid} tunable 2013-01-02 15:34:38 -08:00
nis as ACKed on IRC, drop the unused $Id$ tags everywhere 2010-12-20 12:29:10 -08:00
nvidia Subject: profiles - nvidia abstraction cleanups 2013-01-02 14:39:45 -08:00
openssl add FIPS support to abstractions/openssl 2014-01-03 20:43:43 +01:00
orbit2 fixes for abstractions from Mathias Gug 2007-08-28 23:05:56 +00:00
p11-kit profiles: rw file perms are now needed on AF_UNIX socket files 2013-12-19 23:19:40 -08:00
perl as ACKed on IRC, drop the unused $Id$ tags everywhere 2010-12-20 12:29:10 -08:00
php5 adjust cgi path for php5 abstraction (LP: #538661) 2010-03-30 12:34:32 -05:00
private-files deny writes to upstart user sessions jobs in abstractions/private-files 2013-05-13 14:56:10 -05:00
private-files-strict profiles: rw file perms are now needed on AF_UNIX socket files 2013-12-19 23:19:40 -08:00
python Author: Jamie Strandboge <jamie@canonical.com> 2013-11-04 19:52:57 -06:00
ruby refactor/simplify the regex for ruby abstractions 2013-07-01 11:06:52 -07:00
samba samba (nmbd and smbd) need to create /var/run/samba and /var/cache/samba 2013-12-23 22:15:47 +01:00
smbpass as ACKed on IRC, drop the unused $Id$ tags everywhere 2010-12-20 12:29:10 -08:00
ssl_certs add /var/lib/ca-certificates/ to abstractions/ssl_certs. 2013-11-26 00:41:04 +01:00
ssl_keys as ACKed on IRC, drop the unused $Id$ tags everywhere 2010-12-20 12:29:10 -08:00
svn-repositories as ACKed on IRC, drop the unused $Id$ tags everywhere 2010-12-20 12:29:10 -08:00
ubuntu-bittorrent-clients don't #include ubuntu-helpers in the abstractions. This can only be included 2012-01-11 09:00:35 +01:00
ubuntu-browsers Include IceWeasel in ubuntu-browsers abstraction. 2012-04-25 12:13:15 -07:00
ubuntu-console-browsers don't #include ubuntu-helpers in the abstractions. This can only be included 2012-01-11 09:00:35 +01:00
ubuntu-console-email don't #include ubuntu-helpers in the abstractions. This can only be included 2012-01-11 09:00:35 +01:00
ubuntu-email Adjust path for thunderbird to include non-versioned path 2012-05-18 15:30:22 -05:00
ubuntu-feed-readers don't #include ubuntu-helpers in the abstractions. This can only be included 2012-01-11 09:00:35 +01:00
ubuntu-gnome-terminal update ubuntu abstractions to use '# vim:syntax=apparmor' 2010-12-21 12:53:33 -06:00
ubuntu-helpers Description: let sanitized-helper also allow access to /usr/local. Patch based 2012-07-05 12:36:01 -05:00
ubuntu-konsole Subject: profiles - use @{pid} tunable 2013-01-02 15:34:38 -08:00
ubuntu-media-players don't #include ubuntu-helpers in the abstractions. This can only be included 2012-01-11 09:00:35 +01:00
ubuntu-xterm update for /var/run -> /run udev transition. For compatibility, distributions 2011-07-14 07:57:57 -05:00
user-download abstractions/user-download: 2010-12-22 16:52:13 -06:00
user-mail abstractions/user-mail: 2010-12-22 16:55:18 -06:00
user-manpages From: Christian Boltz <apparmor@cboltz.de> 2011-08-05 13:12:35 -07:00
user-tmp as ACKed on IRC, drop the unused $Id$ tags everywhere 2010-12-20 12:29:10 -08:00
user-write abstractions/user-write: 2010-12-22 16:54:40 -06:00
video fixes for abstractions from Mathias Gug 2007-08-28 23:05:56 +00:00
web-data as ACKed on IRC, drop the unused $Id$ tags everywhere 2010-12-20 12:29:10 -08:00
winbind Make abstractions/winbind work on 64bit systems (valid.dat etc. are in 2011-11-01 18:35:29 +01:00
wutmp Merge k permission for /var/log/lastlog into abstractions/wutmp 2011-08-16 12:26:44 +02:00
X Subject: profiles - owner usage for @{HOME} rules 2013-01-04 22:05:53 -08:00
xad as ACKed on IRC, drop the unused $Id$ tags everywhere 2010-12-20 12:29:10 -08:00
xdg-desktop Create an xdg-desktop abstraction based on the upstream documentation for 2012-01-11 13:00:34 +01:00