Skip to content

Commit

Permalink
profiles: improvements to profiles using private
Browse files Browse the repository at this point in the history
Changes:

* comment `include whitelist-common.inc` when using `private`
* drop `private` on profiles that access files in `${HOME}`
* use `#` in comments

Relates to netblue30#903.
  • Loading branch information
glitsj16 authored and kmk3 committed Aug 10, 2023
1 parent 9f64899 commit eab608f
Show file tree
Hide file tree
Showing 17 changed files with 16 additions and 20 deletions.
3 changes: 1 addition & 2 deletions etc/profile-a-l/daisy.profile
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ include disable-interpreters.inc
include disable-proc.inc
include disable-programs.inc
include disable-shell.inc
#include disable-X11.inc - x11 none
#include disable-X11.inc # x11 none
include disable-xdg.inc

include whitelist-common.inc
Expand Down Expand Up @@ -47,7 +47,6 @@ tracelog
x11 none

disable-mnt
private
private-bin daisy
private-cache
private-dev
Expand Down
5 changes: 2 additions & 3 deletions etc/profile-a-l/dbus-send.profile
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ include disable-shell.inc
include disable-write-mnt.inc
include disable-xdg.inc

include whitelist-common.inc
#include whitelist-common.inc # see #903
include whitelist-runuser-common.inc
include whitelist-usr-share-common.inc
include whitelist-var-common.inc
Expand All @@ -28,8 +28,7 @@ apparmor
caps.drop all
ipc-namespace
machine-id
# Breaks abstract sockets
#net none
#net none # breaks abstract sockets
netfilter
no3d
nodvd
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-a-l/drill.profile
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ include disable-exec.inc
include disable-programs.inc
include disable-xdg.inc

include whitelist-common.inc
#include whitelist-common.inc # see #903
include whitelist-usr-share-common.inc
include whitelist-var-common.inc

Expand Down
2 changes: 1 addition & 1 deletion etc/profile-a-l/gapplication.profile
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ include disable-programs.inc
include disable-shell.inc
include disable-xdg.inc

include whitelist-common.inc
#include whitelist-common.inc # see #903
include whitelist-runuser-common.inc
include whitelist-usr-share-common.inc
include whitelist-var-common.inc
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-a-l/gnome-calendar.profile
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ include disable-shell.inc
include disable-xdg.inc

whitelist /usr/share/libgweather
include whitelist-common.inc
#include whitelist-common.inc # see #903
include whitelist-runuser-common.inc
include whitelist-usr-share-common.inc
include whitelist-var-common.inc
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-a-l/gnubik.profile
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ include disable-shell.inc
include disable-xdg.inc

whitelist /usr/share/gnubik
include whitelist-common.inc
#include whitelist-common.inc # see #903
include whitelist-runuser-common.inc
include whitelist-usr-share-common.inc
include whitelist-var-common.inc
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ include disable-shell.inc
include disable-xdg.inc

whitelist /usr/share/gravity-beams-and-evaporating-stars
include whitelist-common.inc
#include whitelist-common.inc # see #903
include whitelist-usr-share-common.inc
include whitelist-var-common.inc

Expand Down
2 changes: 1 addition & 1 deletion etc/profile-a-l/ipcalc.profile
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ include disable-programs.inc
include disable-write-mnt.inc
include disable-xdg.inc

# include whitelist-common.inc
#include whitelist-common.inc # see #903
include whitelist-runuser-common.inc
include whitelist-usr-share-common.inc
include whitelist-var-common.inc
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-m-z/Xephyr.profile
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ include globals.local
#

whitelist /var/lib/xkb
include whitelist-common.inc
#include whitelist-common.inc # see #903

caps.drop all
# Xephyr needs to be allowed access to the abstract Unix socket namespace.
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-m-z/Xvfb.profile
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ include globals.local
#

whitelist /var/lib/xkb
include whitelist-common.inc
#include whitelist-common.inc # see #903

caps.drop all
# Xvfb needs to be allowed access to the abstract Unix socket namespace.
Expand Down
1 change: 0 additions & 1 deletion etc/profile-m-z/mirrormagic.profile
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,6 @@ seccomp
tracelog

disable-mnt
private
private-bin mirrormagic
private-cache
private-dev
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-m-z/notify-send.profile
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ include disable-shell.inc
include disable-write-mnt.inc
include disable-xdg.inc

include whitelist-common.inc
#include whitelist-common.inc # see #903
include whitelist-runuser-common.inc
include whitelist-usr-share-common.inc
include whitelist-var-common.inc
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-m-z/ping.profile
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ include disable-programs.inc
include disable-X11.inc
include disable-xdg.inc

include whitelist-common.inc
#include whitelist-common.inc # see #903
include whitelist-run-common.inc
include whitelist-runuser-common.inc
include whitelist-usr-share-common.inc
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-m-z/reader.profile
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ include disable-programs.inc
include disable-shell.inc
include disable-xdg.inc

include whitelist-common.inc
#include whitelist-common.inc # see #903
include whitelist-run-common.inc
include whitelist-runuser-common.inc
include whitelist-usr-share-common.inc
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-m-z/seahorse-adventures.profile
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ include disable-xdg.inc

whitelist /usr/share/seahorse-adventures
whitelist /usr/share/games/seahorse-adventures
include whitelist-common.inc
#include whitelist-common.inc # see #903
include whitelist-usr-share-common.inc
include whitelist-var-common.inc

Expand Down
1 change: 0 additions & 1 deletion etc/profile-m-z/wordwarvi.profile
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,6 @@ seccomp
tracelog

disable-mnt
private
private-bin wordwarvi
private-cache
private-dev
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-m-z/xbill.profile
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ include disable-xdg.inc

whitelist /usr/share/xbill
whitelist /var/games/xbill/scores
include whitelist-common.inc
#include whitelist-common.inc # see #903
include whitelist-usr-share-common.inc
include whitelist-var-common.inc

Expand Down

0 comments on commit eab608f

Please sign in to comment.