committing changes in /etc after apt run
Package changes: -acct 6.6.4-4 amd64 +acct 6.6.4-5+b1 amd64 -apparmor 2.13.6-10 amd64 -apt 2.2.4 amd64 +apparmor 3.0.8-3 amd64 +apt 2.6.1 amd64 -apt-utils 2.2.4 amd64 +apt-utils 2.6.1 amd64 -base-passwd 3.5.51 amd64 -bash 5.1-2+deb11u1 amd64 +base-passwd 3.6.1 amd64 +bash 5.2.15-2+b2 amd64 -bind9-dnsutils 1:9.16.42-1~deb11u1 amd64 -bind9-host 1:9.16.42-1~deb11u1 amd64 -bind9-libs 1:9.16.42-1~deb11u1 amd64 -binutils 2.35.2-2 amd64 -binutils-common 2.35.2-2 amd64 -binutils-x86-64-linux-gnu 2.35.2-2 amd64 -bsd-mailx 8.1.2-0.20180807cvs-2 amd64 -bsdextrautils 2.36.1-8+deb11u1 amd64 -bsdutils 1:2.36.1-8+deb11u1 amd64 +bind9-dnsutils 1:9.18.16-1~deb12u1 amd64 +bind9-host 1:9.18.16-1~deb12u1 amd64 +bind9-libs 1:9.18.16-1~deb12u1 amd64 +binutils 2.40-2 amd64 +binutils-common 2.40-2 amd64 +binutils-x86-64-linux-gnu 2.40-2 amd64 +bsd-mailx 8.1.2-0.20220412cvs-1 amd64 +bsdextrautils 2.38.1-5+b1 amd64 +bsdutils 1:2.38.1-5+b1 amd64 -busybox 1:1.30.1-6+b3 amd64 -bzip2 1.0.8-4 amd64 +busybox 1:1.35.0-4+b3 amd64 +bzip2 1.0.8-5+b1 amd64 -chkrootkit 0.54-1+b2 amd64 -clamav 0.103.8+dfsg-0+deb11u1 amd64 -clamav-base 0.103.8+dfsg-0+deb11u1 all -clamav-daemon 0.103.8+dfsg-0+deb11u1 amd64 -clamav-freshclam 0.103.8+dfsg-0+deb11u1 amd64 -clamdscan 0.103.8+dfsg-0+deb11u1 amd64 +chkrootkit 0.57-2+b1 amd64 +clamav 1.0.1+dfsg-2 amd64 +clamav-base 1.0.1+dfsg-2 all +clamav-daemon 1.0.1+dfsg-2 amd64 +clamav-freshclam 1.0.1+dfsg-2 amd64 +clamdscan 1.0.1+dfsg-2 amd64 -cloud-init 20.4.1-2+deb11u1 all +cloud-init 22.4.2-1 all -coreutils 8.32-4+b1 amd64 -cpio 2.13+dfsg-4 amd64 -cpp 4:10.2.1-1 amd64 +coreutils 9.1-1 amd64 +cpio 2.13+dfsg-7.1 amd64 +cpp 4:12.2.0-3 amd64 -cracklib-runtime 2.9.6-3.4 amd64 -cron 3.0pl1-137 amd64 -curl 7.74.0-1.3+deb11u7 amd64 -dash 0.5.11+git20200708+dd9ef66-5 amd64 -dbus 1.12.24-0+deb11u1 amd64 +cpp-12 12.2.0-14 amd64 +cracklib-runtime 2.9.6-5+b1 amd64 +cron 3.0pl1-162 amd64 +cron-daemon-common 3.0pl1-162 all +curl 7.88.1-10+deb12u1 amd64 +dash 0.5.12-2 amd64 +dbus 1.14.8-2~deb12u1 amd64 +dbus-bin 1.14.8-2~deb12u1 amd64 +dbus-daemon 1.14.8-2~deb12u1 amd64 +dbus-session-bus-common 1.14.8-2~deb12u1 all +dbus-system-bus-common 1.14.8-2~deb12u1 all +dbus-user-session 1.14.8-2~deb12u1 amd64 -debianutils 4.11.2 amd64 +debianutils 5.7-0.4 amd64 -diffutils 1:3.7-5 amd64 -dirmngr 2.2.27-2+deb11u2 amd64 -discover 2.1.2-8 amd64 +diffutils 1:3.8-4 amd64 +dirmngr 2.2.40-1.1 amd64 +discover 2.1.2-10 amd64 -dmidecode 3.3-2 amd64 -dmsetup 2:1.02.175-2.1 amd64 +dmidecode 3.4-1 amd64 +dmsetup 2:1.02.185-2 amd64 -dovecot-antispam 2.0+20171229-1+b7 amd64 -dovecot-core 1:2.3.13+dfsg1-2+deb11u1 amd64 -dovecot-imapd 1:2.3.13+dfsg1-2+deb11u1 amd64 -dovecot-lmtpd 1:2.3.13+dfsg1-2+deb11u1 amd64 -dovecot-managesieved 1:2.3.13+dfsg1-2+deb11u1 amd64 -dovecot-mysql 1:2.3.13+dfsg1-2+deb11u1 amd64 -dovecot-pop3d 1:2.3.13+dfsg1-2+deb11u1 amd64 -dovecot-sieve 1:2.3.13+dfsg1-2+deb11u1 amd64 -dpkg 1.20.12 amd64 -dpkg-dev 1.20.12 all -e2fsprogs 1.46.2-2 amd64 -eatmydata 105-9 all -eject 2.36.1-8+deb11u1 amd64 +dovecot-antispam 2.0+20171229-1+b11 amd64 +dovecot-core 1:2.3.19.1+dfsg1-2.1 amd64 +dovecot-imapd 1:2.3.19.1+dfsg1-2.1 amd64 +dovecot-lmtpd 1:2.3.19.1+dfsg1-2.1 amd64 +dovecot-managesieved 1:2.3.19.1+dfsg1-2.1 amd64 +dovecot-mysql 1:2.3.19.1+dfsg1-2.1 amd64 +dovecot-pop3d 1:2.3.19.1+dfsg1-2.1 amd64 +dovecot-sieve 1:2.3.19.1+dfsg1-2.1 amd64 +dpkg 1.21.22 amd64 +dpkg-dev 1.21.22 all +e2fsprogs 1.47.0-2 amd64 +eatmydata 130-2 all +eject 2.38.1-5+b1 amd64 -fakeroot 1.25.3-1.1 amd64 -fdisk 2.36.1-8+deb11u1 amd64 -file 1:5.39-3 amd64 -findutils 4.8.0-1 amd64 +fakeroot 1.31-1.2 amd64 +fdisk 2.38.1-5+b1 amd64 +file 1:5.44-3 amd64 +findutils 4.9.0-4 amd64 -fontconfig 2.13.1-4.2 amd64 +fontconfig 2.14.1-4 amd64 -fonts-urw-base35 20200910-1 all -fuse 2.9.9-5 amd64 -g++ 4:10.2.1-1 amd64 +fonts-urw-base35 20200910-7 all +fuse 2.9.9-6+b1 amd64 +g++ 4:12.2.0-3 amd64 +g++-12 12.2.0-14 amd64 -gawk 1:5.1.0-1 amd64 -gcc 4:10.2.1-1 amd64 +gawk 1:5.2.1-2 amd64 +gcc 4:12.2.0-3 amd64 +gcc-11-base 11.3.0-12 amd64 +gcc-12 12.2.0-14 amd64 +gcc-12-base 12.2.0-14 amd64 -gdisk 1.0.6-1.1 amd64 +gdisk 1.0.9-2.1 amd64 -gettext-base 0.21-4 amd64 -ghostscript 9.53.3~dfsg-7+deb11u5 amd64 -gir1.2-glib-2.0 1.66.1-1+b1 amd64 -git 1:2.30.2-1+deb11u2 amd64 -git-man 1:2.30.2-1+deb11u2 all -gnupg 2.2.27-2+deb11u2 all -gnupg-l10n 2.2.27-2+deb11u2 all -gnupg-utils 2.2.27-2+deb11u2 amd64 -gpg 2.2.27-2+deb11u2 amd64 -gpg-agent 2.2.27-2+deb11u2 amd64 -gpg-wks-client 2.2.27-2+deb11u2 amd64 -gpg-wks-server 2.2.27-2+deb11u2 amd64 -gpgconf 2.2.27-2+deb11u2 amd64 -gpgsm 2.2.27-2+deb11u2 amd64 -gpgv 2.2.27-2+deb11u2 amd64 -grep 3.6-1+deb11u1 amd64 -groff-base 1.22.4-6 amd64 -grub-common 2.06-3~deb11u5 amd64 -grub-pc 2.06-3~deb11u5 amd64 -grub-pc-bin 2.06-3~deb11u5 amd64 -grub2-common 2.06-3~deb11u5 amd64 -gsfonts 1:8.11+urwcyr1.0.7~pre44-4.5 all -gzip 1.10-4+deb11u1 amd64 -hdparm 9.60+ds-1 amd64 +gettext-base 0.21-12 amd64 +ghostscript 10.0.0~dfsg-11+deb12u1 amd64 +gir1.2-glib-2.0 1.74.0-3 amd64 +git 1:2.39.2-1.1 amd64 +git-man 1:2.39.2-1.1 all +gnupg 2.2.40-1.1 all +gnupg-l10n 2.2.40-1.1 all +gnupg-utils 2.2.40-1.1 amd64 +gpg 2.2.40-1.1 amd64 +gpg-agent 2.2.40-1.1 amd64 +gpg-wks-client 2.2.40-1.1 amd64 +gpg-wks-server 2.2.40-1.1 amd64 +gpgconf 2.2.40-1.1 amd64 +gpgsm 2.2.40-1.1 amd64 +gpgv 2.2.40-1.1 amd64 +grep 3.8-5 amd64 +groff-base 1.22.4-10 amd64 +grub-common 2.06-13 amd64 +grub-pc 2.06-13 amd64 +grub-pc-bin 2.06-13 amd64 +grub2-common 2.06-13 amd64 +gsfonts 2:20200910-7 all +gzip 1.12-1 amd64 +hdparm 9.65+ds-1 amd64 -hostname 3.23 amd64 -htop 3.0.5-7 amd64 -iamerican 3.4.02-2 all -ibritish 3.4.02-2 all -ienglish-common 3.4.02-2 all -ifupdown 0.8.36 amd64 +hostname 3.23+nmu1 amd64 +htop 3.2.2-2 amd64 +iamerican 3.4.05-1 all +ibritish 3.4.05-1 all +ienglish-common 3.4.05-1 all +ifupdown 0.8.41 amd64 -imagemagick-6.q16 8:6.9.11.60+dfsg-1.3+deb11u1 amd64 +imagemagick-6.q16 8:6.9.11.60+dfsg-1.6 amd64 +inetutils-telnet 2:2.4-2 amd64 -init-system-helpers 1.60 all +init-system-helpers 1.65.2 all -iproute2 5.10.0-4 amd64 -iptables 1.8.7-1 amd64 -iputils-ping 3:20210202-1 amd64 -isc-dhcp-client 4.4.1-2.3+deb11u2 amd64 +iproute2 6.1.0-3 amd64 +iptables 1.8.9-2 amd64 +iputils-ping 3:20221126-1 amd64 +isc-dhcp-client 4.4.3-P1-2 amd64 -ispell 3.4.02-2 amd64 +ispell 3.4.05-1 amd64 -kbd 2.3.0-3 amd64 +kbd 2.5.1-1+b1 amd64 -kmod 28-1 amd64 +kmod 30+20221128-1 amd64 -less 551-2 amd64 +less 590-2 amd64 -libacl1 2.2.53-10 amd64 +libacl1 2.3.1-3 amd64 -libalgorithm-diff-xs-perl 0.04-6+b1 amd64 +libalgorithm-diff-xs-perl 0.04-8+b1 amd64 -libapparmor1 2.13.6-10 amd64 +libaom3 3.6.0-1 amd64 +libapparmor1 3.0.8-3 amd64 -libapt-pkg-perl 0.1.39 amd64 +libapt-pkg-perl 0.1.40+b2 amd64 -libapt-pkg6.0 2.2.4 amd64 +libapt-pkg6.0 2.6.1 amd64 -libargon2-1 0~20171227-0.2 amd64 -libasan6 10.2.1-6 amd64 -libassuan0 2.5.3-7.1 amd64 -libatomic1 10.2.1-6 amd64 +libargon2-1 0~20171227-0.3+deb12u1 amd64 +libasan6 11.3.0-12 amd64 +libasan8 12.2.0-14 amd64 +libassuan0 2.5.5-5 amd64 +libatomic1 12.2.0-14 amd64 -libaudit1 1:3.0-2 amd64 +libaudit1 1:3.0.9-1 amd64 -libavahi-client3 0.8-5+deb11u2 amd64 -libavahi-common-data 0.8-5+deb11u2 amd64 -libavahi-common3 0.8-5+deb11u2 amd64 +libavahi-client3 0.8-10 amd64 +libavahi-common-data 0.8-10 amd64 +libavahi-common3 0.8-10 amd64 -libberkeleydb-perl 0.64-1+b1 amd64 -libbinutils 2.35.2-2 amd64 +libberkeleydb-perl 0.64-2+b1 amd64 +libbinutils 2.40-2 amd64 -libblkid1 2.36.1-8+deb11u1 amd64 +libblkid1 2.38.1-5+b1 amd64 +libbpf1 1:1.1.0-1 amd64 -libbsd0 0.11.3-1 amd64 -libbz2-1.0 1.0.8-4 amd64 -libc-bin 2.31-13+deb11u6 amd64 -libc-client2007e 8:2007f~dfsg-7+b1 amd64 -libc-dev-bin 2.31-13+deb11u6 amd64 -libc-devtools 2.31-13+deb11u6 amd64 +libbsd0 0.11.7-2 amd64 +libbz2-1.0 1.0.8-5+b1 amd64 +libc-bin 2.36-9+deb12u1 amd64 +libc-client2007e 8:2007f~dfsg-7+b2 amd64 +libc-dev-bin 2.36-9+deb12u1 amd64 +libc-devtools 2.36-9+deb12u1 amd64 -libc6 2.31-13+deb11u6 amd64 -libc6-dev 2.31-13+deb11u6 amd64 -libcairo2 1.16.0-5 amd64 -libcap-ng0 0.7.9-2.2+b1 amd64 -libcap2 1:2.44-1 amd64 -libcap2-bin 1:2.44-1 amd64 +libc6 2.36-9+deb12u1 amd64 +libc6-dev 2.36-9+deb12u1 amd64 +libcairo2 1.16.0-7 amd64 +libcap-ng0 0.8.3-1+b3 amd64 +libcap2 1:2.66-4 amd64 +libcap2-bin 1:2.66-4 amd64 -libcc1-0 10.2.1-6 amd64 +libcbor0.8 0.8.0-2+b1 amd64 +libcc1-0 12.2.0-14 amd64 +libclamav11 1.0.1+dfsg-2 amd64 -libclone-perl 0.45-1+b1 amd64 +libclone-perl 0.46-1 amd64 -libcommon-sense-perl 3.75-1+b4 amd64 +libcommon-sense-perl 3.75-3 amd64 -libconvert-uulib-perl 1:1.5~dfsg-1+b3 amd64 +libconvert-uulib-perl 1:1.8+dfsg-1 amd64 -libcrypt-dev 1:4.4.18-4 amd64 -libcrypt-openssl-bignum-perl 0.09-1+b3 amd64 -libcrypt-openssl-random-perl 0.15-2+b1 amd64 -libcrypt-openssl-rsa-perl 0.31-1+b3 amd64 -libcrypt1 1:4.4.18-4 amd64 -libcryptsetup12 2:2.3.7-1+deb11u1 amd64 +libcrypt-dev 1:4.4.33-2 amd64 +libcrypt-openssl-bignum-perl 0.09-2+b1 amd64 +libcrypt-openssl-random-perl 0.15-3+b1 amd64 +libcrypt-openssl-rsa-perl 0.33-3+b1 amd64 +libcrypt1 1:4.4.33-2 amd64 +libcryptsetup12 2:2.6.1-4~deb12u1 amd64 -libctf0 2.35.2-2 amd64 -libcups2 2.3.3op2-3+deb11u2 amd64 -libcurl3-gnutls 7.74.0-1.3+deb11u7 amd64 -libcurl4 7.74.0-1.3+deb11u7 amd64 +libctf0 2.40-2 amd64 +libcups2 2.4.2-3+deb12u1 amd64 +libcurl3-gnutls 7.88.1-10+deb12u1 amd64 +libcurl4 7.88.1-10+deb12u1 amd64 -libdaxctl1 71.1-1 amd64 -libdb5.3 5.3.28+dfsg1-0.8 amd64 -libdbd-mariadb-perl 1.21-3 amd64 -libdbd-mysql-perl 4.050-3+b1 amd64 -libdbi-perl 1.643-3+b1 amd64 -libdbus-1-3 1.12.24-0+deb11u1 amd64 -libde265-0 1.0.11-0+deb11u1 amd64 +libdav1d6 1.0.0-2 amd64 +libdaxctl1 76.1-1 amd64 +libdb5.3 5.3.28+dfsg2-1 amd64 +libdbd-mariadb-perl 1.22-1+b1 amd64 +libdbd-mysql-perl 4.050-5+b1 amd64 +libdbi-perl 1.643-4 amd64 +libdbus-1-3 1.14.8-2~deb12u1 amd64 +libde265-0 1.0.11-1 amd64 -libdevmapper1.02.1 2:1.02.175-2.1 amd64 +libdevmapper1.02.1 2:1.02.185-2 amd64 -libdiscover2 2.1.2-8 amd64 +libdiscover2 2.1.2-10 amd64 -libdjvulibre21 3.5.28-2 amd64 +libdjvulibre21 3.5.28-2+b1 amd64 -libdpkg-perl 1.20.12 all -libeatmydata1 105-9 amd64 -libedit2 3.1-20191231-2+b1 amd64 +libdpkg-perl 1.21.22 all +libeatmydata1 130-2+b1 amd64 +libedit2 3.1-20221030-2 amd64 -libelf1 0.183-1 amd64 +libelf1 0.188-2.1 amd64 -libevent-2.1-7 2.1.12-stable-1 amd64 -libevent-core-2.1-7 2.1.12-stable-1 amd64 -libevent-pthreads-2.1-7 2.1.12-stable-1 amd64 +libevent-2.1-7 2.1.12-stable-8 amd64 +libevent-core-2.1-7 2.1.12-stable-8 amd64 +libevent-pthreads-2.1-7 2.1.12-stable-8 amd64 -libext2fs2 1.46.2-2 amd64 +libext2fs2 1.47.0-2 amd64 -libfakeroot 1.25.3-1.1 amd64 +libfakeroot 1.31-1.2 amd64 -libfcgi-perl 0.79+ds-2 amd64 +libfcgi-perl 0.82+ds-2 amd64 -libfdisk1 2.36.1-8+deb11u1 amd64 +libfdisk1 2.38.1-5+b1 amd64 -libfftw3-double3 3.3.8-2 amd64 -libfido2-1 1.6.0-2 amd64 -libfile-fcntllock-perl 0.22-3+b7 amd64 -libfile-fnmatch-perl 0.02-2+b8 amd64 -libfontconfig1 2.13.1-4.2 amd64 -libfreetype6 2.10.4+dfsg-1+deb11u1 amd64 +libffi8 3.4.4-1 amd64 +libfftw3-double3 3.3.10-1 amd64 +libfido2-1 1.12.0-2+b1 amd64 +libfile-fcntllock-perl 0.22-4+b1 amd64 +libfile-find-rule-perl 0.34-3 all +libfile-fnmatch-perl 0.02-3+b1 amd64 +libfontconfig1 2.14.1-4 amd64 +libfontenc1 1:1.1.4-1 amd64 +libfreetype6 2.12.1+dfsg-5 amd64 -libfstrm0 0.6.0-1+b1 amd64 -libfuse2 2.9.9-5 amd64 +libfstrm0 0.6.1-1 amd64 +libfuse2 2.9.9-6+b1 amd64 -libgcc-s1 10.2.1-6 amd64 +libgcc-12-dev 12.2.0-14 amd64 +libgcc-s1 12.2.0-14 amd64 -libgcrypt20 1.8.7-6 amd64 +libgcrypt20 1.10.1-3 amd64 -libgdbm-compat4 1.19-2 amd64 -libgdbm6 1.19-2 amd64 -libgeoip1 1.6.12-7 amd64 -libgirepository-1.0-1 1.66.1-1+b1 amd64 -libglib2.0-0 2.66.8-1 amd64 +libgdbm-compat4 1.23-3 amd64 +libgdbm6 1.23-3 amd64 +libgeoip1 1.6.12-10 amd64 +libgirepository-1.0-1 1.74.0-3 amd64 +libglib2.0-0 2.74.6-2 amd64 -libgnutls30 3.7.1-5+deb11u3 amd64 -libgomp1 10.2.1-6 amd64 -libgpg-error0 1.38-2 amd64 +libgnutls30 3.7.9-2 amd64 +libgomp1 12.2.0-14 amd64 +libgpg-error0 1.46-1 amd64 +libgprofng0 2.40-2 amd64 -libgs9 9.53.3~dfsg-7+deb11u5 amd64 -libgs9-common 9.53.3~dfsg-7+deb11u5 all -libgssapi-krb5-2 1.18.3-6+deb11u3 amd64 -libharfbuzz0b 2.7.4-1 amd64 -libheif1 1.11.0-1 amd64 +libgs-common 10.0.0~dfsg-11+deb12u1 all +libgs10 10.0.0~dfsg-11+deb12u1 amd64 +libgs10-common 10.0.0~dfsg-11+deb12u1 all +libgs9-common 10.0.0~dfsg-11+deb12u1 all +libgssapi-krb5-2 1.20.1-2 amd64 +libharfbuzz0b 6.0.0+dfsg-3 amd64 +libhashkit2 1.1.4-1 amd64 +libheif1 1.15.1-1 amd64 -libhtml-parser-perl 3.75-1+b1 amd64 +libhtml-parser-perl 3.81-1 amd64 -libhttp-message-perl 6.28-1 all +libhttp-message-perl 6.44-1 all +libice6 2:1.0.10-1 amd64 +libicu72 72.1-3 amd64 +libidn12 1.41-1 amd64 +libimath-3-1-29 3.1.6-1 amd64 -libip4tc2 1.8.7-1 amd64 +libip4tc2 1.8.9-2 amd64 -libip6tc2 1.8.7-1 amd64 -libiptc0 1.8.7-1 amd64 +libip6tc2 1.8.9-2 amd64 +libiptc0 1.8.9-2 amd64 -libitm1 10.2.1-6 amd64 +libitm1 12.2.0-14 amd64 +libjansson4 2.14-2 amd64 -libjemalloc2 5.2.1-3 amd64 +libjemalloc2 5.3.0-1 amd64 -libjson-c5 0.15-2 amd64 +libjson-c5 0.16-2 amd64 -libjson-xs-perl 4.030-1+b1 amd64 +libjson-xs-perl 4.030-2+b1 amd64 -libk5crypto3 1.18.3-6+deb11u3 amd64 +libk5crypto3 1.20.1-2 amd64 -libkmod2 28-1 amd64 -libkrb5-3 1.18.3-6+deb11u3 amd64 -libkrb5support0 1.18.3-6+deb11u3 amd64 -libksba8 1.5.0-3+deb11u2 amd64 +libkmod2 30+20221128-1 amd64 +libkrb5-3 1.20.1-2 amd64 +libkrb5support0 1.20.1-2 amd64 +libksba8 1.6.3-2 amd64 +libldap-2.5-0 2.5.13+dfsg-5 amd64 +liblerc4 4.0.0+ds-2 amd64 -liblocale-gettext-perl 1.07-4+b1 amd64 +liblocale-gettext-perl 1.07-5 amd64 -liblsan0 10.2.1-6 amd64 -libltdl7 2.4.6-15 amd64 +liblsan0 12.2.0-14 amd64 +libltdl7 2.4.7-5 amd64 -liblua5.3-0 5.3.3-1.1+b1 amd64 +liblua5.3-0 5.3.6-2 amd64 +liblua5.4-0 5.4.4-3 amd64 -liblzma5 5.2.5-2.1~deb11u1 amd64 -libmagic-mgc 1:5.39-3 amd64 -libmagic1 1:5.39-3 amd64 -libmagickcore-6.q16-6 8:6.9.11.60+dfsg-1.3+deb11u1 amd64 -libmagickcore-6.q16-6-extra 8:6.9.11.60+dfsg-1.3+deb11u1 amd64 +liblzma5 5.4.1-0.2 amd64 +liblzo2-2 2.10-2 amd64 +libmagic-mgc 1:5.44-3 amd64 +libmagic1 1:5.44-3 amd64 +libmagickcore-6.q16-6 8:6.9.11.60+dfsg-1.6 amd64 +libmagickcore-6.q16-6-extra 8:6.9.11.60+dfsg-1.6 amd64 -libmariadb3 1:10.9.8+maria~deb11 amd64 -libmaxminddb0 1.5.2-1 amd64 -libmd0 1.0.3-3 amd64 -libmemcached11 1.0.18-4.2 amd64 -libmilter1.0.1 8.15.2-22 amd64 +libmariadb3 1:10.11.3-1 amd64 +libmaxminddb0 1.7.1-1 amd64 +libmd0 1.0.4-2 amd64 +libmemcached11 1.1.4-1 amd64 +libmilter1.0.1 8.17.1.9-2 amd64 -libmount1 2.36.1-8+deb11u1 amd64 +libmount1 2.38.1-5+b1 amd64 -libncurses6 6.2+20201114-2+deb11u1 amd64 -libncursesw6 6.2+20201114-2+deb11u1 amd64 -libndctl6 71.1-1 amd64 +libncurses6 6.4-4 amd64 +libncursesw6 6.4-4 amd64 +libndctl6 76.1-1 amd64 -libnet-dns-sec-perl 1.18-1+b1 amd64 +libnet-dns-sec-perl 1.20-1+b1 amd64 -libnet-libidn-perl 0.12.ds-3+b3 amd64 -libnet-patricia-perl 1.22-1+b7 amd64 +libnet-libidn-perl 0.12.ds-4+b1 amd64 +libnet-patricia-perl 1.22-2+b1 amd64 -libnet-ssleay-perl 1.88-3+b1 amd64 -libnetaddr-ip-perl 4.079+dfsg-1+b5 amd64 +libnet-ssleay-perl 1.92-2+b1 amd64 +libnetaddr-ip-perl 4.079+dfsg-2+b1 amd64 +libnetpbm11 2:11.01.00-2 amd64 -libnewt0.52 0.52.21-4+b3 amd64 +libnewt0.52 0.52.23-1+b1 amd64 -libnftnl11 1.1.9-1 amd64 +libnftnl11 1.2.4-2 amd64 -libnginx-mod-http-geoip 1.18.0-6.1+deb11u3 amd64 -libnginx-mod-http-image-filter 1.18.0-6.1+deb11u3 amd64 -libnginx-mod-http-xslt-filter 1.18.0-6.1+deb11u3 amd64 -libnginx-mod-mail 1.18.0-6.1+deb11u3 amd64 -libnginx-mod-stream 1.18.0-6.1+deb11u3 amd64 -libnginx-mod-stream-geoip 1.18.0-6.1+deb11u3 amd64 -libnl-3-200 3.4.0-1+b1 amd64 -libnl-genl-3-200 3.4.0-1+b1 amd64 +libnginx-mod-http-geoip 1.22.1-9 amd64 +libnginx-mod-http-image-filter 1.22.1-9 amd64 +libnginx-mod-http-xslt-filter 1.22.1-9 amd64 +libnginx-mod-mail 1.22.1-9 amd64 +libnginx-mod-stream 1.22.1-9 amd64 +libnginx-mod-stream-geoip 1.22.1-9 amd64 +libnl-3-200 3.7.0-0.2+b1 amd64 +libnl-genl-3-200 3.7.0-0.2+b1 amd64 -libnss-systemd 247.3-7+deb11u4 amd64 -libnuma1 2.0.12-1+b1 amd64 +libnss-systemd 252.12-1~deb12u1 amd64 +libnuma1 2.0.16-1 amd64 +libnumber-compare-perl 0.03-3 all -libopendbx1 1.4.6-15 amd64 -libopendbx1-sqlite3 1.4.6-15 amd64 -libopendkim11 2.11.0~beta2-4 amd64 +libopendbx1 1.4.6-16+b1 amd64 +libopendbx1-sqlite3 1.4.6-16+b1 amd64 +libopendkim11 2.11.0~beta2-8 amd64 +libopenexr-3-1-30 3.1.5-5 amd64 -libopenjp2-7 2.4.0-3 amd64 -libopts25 1:5.18.16-4 amd64 -libp11-kit0 0.23.22-1 amd64 -libpam-modules 1.4.0-9+deb11u1 amd64 -libpam-modules-bin 1.4.0-9+deb11u1 amd64 +libopenjp2-7 2.5.0-2 amd64 +libopts25 1:5.18.16-5 amd64 +libp11-kit0 0.24.1-2 amd64 +libpam-modules 1.5.2-6 amd64 +libpam-modules-bin 1.5.2-6 amd64 -libpam-systemd 247.3-7+deb11u4 amd64 -libpam0g 1.4.0-9+deb11u1 amd64 -libpango-1.0-0 1.46.2-3 amd64 -libpangocairo-1.0-0 1.46.2-3 amd64 -libpangoft2-1.0-0 1.46.2-3 amd64 -libpaper-utils 1.1.28+b1 amd64 -libpaper1 1.1.28+b1 amd64 +libpam-systemd 252.12-1~deb12u1 amd64 +libpam0g 1.5.2-6 amd64 +libpango-1.0-0 1.50.12+ds-1 amd64 +libpangocairo-1.0-0 1.50.12+ds-1 amd64 +libpangoft2-1.0-0 1.50.12+ds-1 amd64 +libpaper-utils 1.1.29 amd64 +libpaper1 1.1.29 amd64 -libpcap0.8 1.10.0-2 amd64 -libpci3 1:3.7.0-5 amd64 -libpcre2-8-0 10.40-1+0~20220713.16+debian11~1.gbpb6cec5 amd64 -libpcre3 2:8.45-1+0~20230620.10+debian11~1.gbp8792c4 amd64 +libpcap0.8 1.10.3-1 amd64 +libpci3 1:3.9.0-4 amd64 +libpcre2-8-0 10.42-1 amd64 +libpcre3 2:8.45-1+0~20230620.10+debian12~1.gbp8792c4 amd64 -libpipeline1 1.5.3-1 amd64 +libperl5.36 5.36.0-7 amd64 +libpipeline1 1.5.7-1 amd64 -libpmem1 1.10-2+deb11u1 amd64 +libpmem1 1.12.1-2 amd64 -libpopt0 1.18-2 amd64 +libpopt0 1.19+dfsg-1 amd64 +libproc2-0 2:4.0.2-3 amd64 -libpsl5 0.21.0-1.2 amd64 +libpsl5 0.21.2-1 amd64 -libpwquality1 1.4.4-1 amd64 +libpwquality1 1.4.5-1+b1 amd64 -libpython3-stdlib 3.9.2-3 amd64 +libpython3-stdlib 3.11.2-1+b1 amd64 +libpython3.11 3.11.2-6 amd64 +libpython3.11-minimal 3.11.2-6 amd64 +libpython3.11-stdlib 3.11.2-6 amd64 -libquadmath0 10.2.1-6 amd64 -librbl1 2.11.0~beta2-4 amd64 -libreadline8 8.1-1 amd64 +libquadmath0 12.2.0-14 amd64 +librbl1 2.11.0~beta2-8 amd64 +libreadline8 8.2-1.3 amd64 +libregexp-ipv6-perl 0.03-3 all +libruby 1:3.1 amd64 -libsasl2-2 2.1.27+dfsg-2.1+deb11u1 amd64 -libsasl2-modules 2.1.27+dfsg-2.1+deb11u1 amd64 +libruby3.1 3.1.2-7 amd64 +libsasl2-2 2.1.28+dfsg-10 amd64 +libsasl2-modules 2.1.28+dfsg-10 amd64 -libselinux1 3.1-3 amd64 -libsemanage-common 3.1-1 all -libsemanage1 3.1-1+b2 amd64 +libselinux1 3.4-1+b6 amd64 +libsemanage-common 3.4-1 all +libsemanage2 3.4-1+b5 amd64 -libsensors5 1:3.6.0-7 amd64 +libsensors5 1:3.6.0-7.1 amd64 +libsepol2 3.4-2.1 amd64 -libslang2 2.3.2-5 amd64 -libsmartcols1 2.36.1-8+deb11u1 amd64 -libsocket6-perl 0.29-1+b3 amd64 +libslang2 2.3.3-3 amd64 +libsm6 2:1.2.3-1 amd64 +libsmartcols1 2.38.1-5+b1 amd64 +libsnappy1v5 1.1.9-3 amd64 +libsocket6-perl 0.29-3 amd64 -libsqlite3-0 3.34.1-3 amd64 -libss2 1.46.2-2 amd64 -libssh2-1 1.9.0-2 amd64 +libsqlite3-0 3.40.1-2 amd64 +libss2 1.47.0-2 amd64 +libssh2-1 1.10.0-3+b1 amd64 +libssl3 3.0.9-1 amd64 -libstdc++6 10.2.1-6 amd64 +libstdc++-12-dev 12.2.0-14 amd64 +libstdc++6 12.2.0-14 amd64 -libsys-cpu-perl 0.61-2+b6 amd64 -libsys-meminfo-perl 0.99-1+b5 amd64 -libsystemd0 247.3-7+deb11u4 amd64 +libsys-cpu-perl 0.61-3+b1 amd64 +libsys-meminfo-perl 0.99-2+b1 amd64 +libsystemd-shared 252.12-1~deb12u1 amd64 +libsystemd0 252.12-1~deb12u1 amd64 -libterm-readkey-perl 2.38-1+b2 amd64 -libtext-charwidth-perl 0.04-10+b1 amd64 -libtext-iconv-perl 1.7-7+b1 amd64 +libterm-readkey-perl 2.38-2+b1 amd64 +libtext-charwidth-perl 0.04-11 amd64 +libtext-glob-perl 0.11-3 all +libtext-iconv-perl 1.7-8 amd64 +libtiff6 4.5.0-6 amd64 -libtinfo6 6.2+20201114-2+deb11u1 amd64 +libtinfo6 6.4-4 amd64 -libtirpc-dev 1.3.1-1+deb11u1 amd64 -libtirpc3 1.3.1-1+deb11u1 amd64 -libtsan0 10.2.1-6 amd64 +libtirpc-dev 1.3.3+ds-1 amd64 +libtirpc3 1.3.3+ds-1 amd64 +libtsan0 11.3.0-12 amd64 +libtsan2 12.2.0-14 amd64 -libubsan1 10.2.1-6 amd64 +libubsan1 12.2.0-14 amd64 -libudev1 247.3-7+deb11u4 amd64 -libunbound8 1.13.1-1+deb11u1 amd64 -libunistring2 0.9.10-4 amd64 -libunix-syslog-perl 1.1-3+b3 amd64 -libunwind8 1.3.2-2 amd64 -liburi-perl 5.08-1 all +libudev1 252.12-1~deb12u1 amd64 +libunbound8 1.17.1-2 amd64 +libunistring2 1.0-2 amd64 +libunix-syslog-perl 1.1-4+b1 amd64 +libunwind8 1.6.2-3 amd64 +liburi-perl 5.17-1 all +liburing2 2.3-3 amd64 -libutempter0 1.2.1-2 amd64 +libutempter0 1.2.1-3 amd64 -libuv1 1.40.0-2 amd64 -libvbr2 2.11.0~beta2-4 amd64 +libuv1 1.44.2-1 amd64 +libvbr2 2.11.0~beta2-8 amd64 -libwebpdemux2 0.6.1-2.1+deb11u1 amd64 -libwebpmux3 0.6.1-2.1+deb11u1 amd64 -libwmf0.2-7 0.2.8.4-17 amd64 -libwrap0 7.6.q-31 amd64 -libx11-6 2:1.7.2-1+deb11u1 amd64 +libwebp7 1.2.4-0.2 amd64 +libwebpdemux2 1.2.4-0.2 amd64 +libwebpmux3 1.2.4-0.2 amd64 +libwmf-0.2-7 0.2.12-5.1 amd64 +libwmf0.2-7 0.2.12-5.1 amd64 +libwmflite-0.2-7 0.2.12-5.1 amd64 +libwrap0 7.6.q-32 amd64 +libx11-6 2:1.8.4-2+deb12u1 amd64 +libx265-199 3.5-2+b1 amd64 -libxml2 2.9.14+dfsg-0.1+0~20230421.14+debian11~1.gbpf14485 amd64 +libxml2 2.9.14+dfsg-1.3~deb12u1 amd64 -libxpm4 1:3.5.12-1.1~deb11u1 amd64 +libxpm4 1:3.5.12-1.1 amd64 -libxslt1.1 1.1.34-4+deb11u1 amd64 -libxtables12 1.8.7-1 amd64 +libxslt1.1 1.1.35-1 amd64 +libxt6 1:1.2.1-1.1 amd64 +libxtables12 1.8.9-2 amd64 -libzip4 1.7.3-1 amd64 -libzstd1 1.4.8+dfsg-2.1 amd64 +libzip4 1.7.3-1+b1 amd64 +libzstd1 1.5.4+dfsg2-5 amd64 +linux-compiler-gcc-12-x86 6.1.38-4 amd64 -linux-headers-amd64 5.10.179-5 amd64 +linux-headers-6.1.0-11-amd64 6.1.38-4 amd64 +linux-headers-6.1.0-11-common 6.1.38-4 all +linux-headers-amd64 6.1.38-4 amd64 +linux-kbuild-6.1 6.1.38-4 amd64 -lm-sensors 1:3.6.0-7 amd64 -locales 2.31-13+deb11u6 all -login 1:4.8.1-1 amd64 -logrotate 3.18.0-2+deb11u1 amd64 -logsave 1.46.2-2 amd64 +lm-sensors 1:3.6.0-7.1 amd64 +locales 2.36-9+deb12u1 all +login 1:4.13+dfsg1-1+b1 amd64 +logrotate 3.21.0-1 amd64 +logsave 1.47.0-2 amd64 -lsb-base 11.1.0 all +lsb-base 11.6 all -lsof 4.93.2+dfsg-1.1 amd64 +lsof 4.95.0-1 amd64 -man-db 2.9.4-2 amd64 +man-db 2.11.2-2 amd64 -mariadb-client 1:10.9.8+maria~deb11 amd64 -mariadb-client-core 1:10.9.8+maria~deb11 amd64 +mariadb-client 1:10.11.3-1 amd64 +mariadb-client-core 1:10.11.3-1 amd64 -mariadb-server 1:10.9.8+maria~deb11 amd64 -mariadb-server-core 1:10.9.8+maria~deb11 amd64 +mariadb-plugin-provider-bzip2 1:10.11.3-1 amd64 +mariadb-plugin-provider-lz4 1:10.11.3-1 amd64 +mariadb-plugin-provider-lzma 1:10.11.3-1 amd64 +mariadb-plugin-provider-lzo 1:10.11.3-1 amd64 +mariadb-plugin-provider-snappy 1:10.11.3-1 amd64 +mariadb-server 1:10.11.3-1 amd64 +mariadb-server-core 1:10.11.3-1 amd64 -memcached 1.6.9+dfsg-1 amd64 +memcached 1.6.18-1 amd64 -mlocate 0.26-5 amd64 -mlock 8:2007f~dfsg-7+b1 amd64 -mount 2.36.1-8+deb11u1 amd64 +mlocate 1.1.18-1 all +mlock 8:2007f~dfsg-7+b2 amd64 +mount 2.38.1-5+b1 amd64 -nano 5.4-2+deb11u2 amd64 -ncal 12.1.7+nmu3 amd64 -ncurses-base 6.2+20201114-2+deb11u1 all -ncurses-bin 6.2+20201114-2+deb11u1 amd64 -ncurses-term 6.2+20201114-2+deb11u1 all -net-tools 1.60+git20181103.0eebece-1 amd64 +nano 7.2-1 amd64 +ncal 12.1.8 amd64 +ncurses-base 6.4-4 all +ncurses-bin 6.4-4 amd64 +ncurses-term 6.4-4 all +net-tools 2.10-0.1 amd64 -netpbm 2:10.0-15.4 amd64 -nginx 1.18.0-6.1+deb11u3 all -nginx-common 1.18.0-6.1+deb11u3 all -nginx-core 1.18.0-6.1+deb11u3 amd64 -nmap 7.91+dfsg1+really7.80+dfsg1-2 amd64 -nmap-common 7.91+dfsg1+really7.80+dfsg1-2 all +netpbm 2:11.01.00-2 amd64 +nginx 1.22.1-9 amd64 +nginx-common 1.22.1-9 all +nginx-core 1.22.1-9 all +nmap 7.93+dfsg1-1 amd64 +nmap-common 7.93+dfsg1-1 all -ntp 1:4.2.8p15+dfsg-1 amd64 -ntpdate 1:4.2.8p15+dfsg-1 amd64 -opendkim 2.11.0~beta2-4 amd64 -opendkim-tools 2.11.0~beta2-4 amd64 -openssh-client 1:8.4p1-5+deb11u1 amd64 -openssh-server 1:8.4p1-5+deb11u1 amd64 -openssh-sftp-server 1:8.4p1-5+deb11u1 amd64 -openssl 1.1.1n-0+deb11u5 amd64 +ntp 1:4.2.8p15+dfsg-2~1.2.2+dfsg1-1+deb12u1 all +ntpdate 1:4.2.8p15+dfsg-2~1.2.2+dfsg1-1+deb12u1 all +ntpsec 1.2.2+dfsg1-1+deb12u1 amd64 +ntpsec-ntpdate 1.2.2+dfsg1-1+deb12u1 amd64 +ntpsec-ntpdig 1.2.2+dfsg1-1+deb12u1 amd64 +opendkim 2.11.0~beta2-8 amd64 +opendkim-tools 2.11.0~beta2-8 amd64 +openssh-client 1:9.2p1-2 amd64 +openssh-server 1:9.2p1-2 amd64 +openssh-sftp-server 1:9.2p1-2 amd64 +openssl 3.0.9-1 amd64 -passwd 1:4.8.1-1 amd64 +passwd 1:4.13+dfsg1-1+b1 amd64 -pciutils 1:3.7.0-5 amd64 -perl 5.32.1-4+deb11u2 amd64 -perl-base 5.32.1-4+deb11u2 amd64 +pciutils 1:3.9.0-4 amd64 +perl 5.36.0-7 amd64 +perl-base 5.36.0-7 amd64 -perl-openssl-defaults 5 amd64 +perl-modules-5.36 5.36.0-7 all +perl-openssl-defaults 7+b1 amd64 -php8.1-apcu 5.1.22++-1+0~20230618.37+debian11~1.gbp7134d4 amd64 -php8.1-bcmath 8.1.22-1+0~20230815.49+debian11~1.gbp8da143 amd64 -php8.1-cgi 8.1.22-1+0~20230815.49+debian11~1.gbp8da143 amd64 -php8.1-cli 8.1.22-1+0~20230815.49+debian11~1.gbp8da143 amd64 -php8.1-common 8.1.22-1+0~20230815.49+debian11~1.gbp8da143 amd64 -php8.1-curl 8.1.22-1+0~20230815.49+debian11~1.gbp8da143 amd64 -php8.1-fpm 8.1.22-1+0~20230815.49+debian11~1.gbp8da143 amd64 -php8.1-gd 8.1.22-1+0~20230815.49+debian11~1.gbp8da143 amd64 -php8.1-gmp 8.1.22-1+0~20230815.49+debian11~1.gbp8da143 amd64 +php8.1-apcu 5.1.22++-1+0~20230618.37+debian12~1.gbp7134d4 amd64 +php8.1-bcmath 8.1.22-1+0~20230815.49+debian12~1.gbp8da143 amd64 +php8.1-cgi 8.1.22-1+0~20230815.49+debian12~1.gbp8da143 amd64 +php8.1-cli 8.1.22-1+0~20230815.49+debian12~1.gbp8da143 amd64 +php8.1-common 8.1.22-1+0~20230815.49+debian12~1.gbp8da143 amd64 +php8.1-curl 8.1.22-1+0~20230815.49+debian12~1.gbp8da143 amd64 +php8.1-fpm 8.1.22-1+0~20230815.49+debian12~1.gbp8da143 amd64 +php8.1-gd 8.1.22-1+0~20230815.49+debian12~1.gbp8da143 amd64 +php8.1-gmp 8.1.22-1+0~20230815.49+debian12~1.gbp8da143 amd64 -php8.1-imagick 3.7.0-4+0~20230701.41+debian11~1.gbpbf7e27 amd64 -php8.1-imap 8.1.22-1+0~20230815.49+debian11~1.gbp8da143 amd64 -php8.1-intl 8.1.22-1+0~20230815.49+debian11~1.gbp8da143 amd64 -php8.1-mbstring 8.1.22-1+0~20230815.49+debian11~1.gbp8da143 amd64 +php8.1-imagick 3.7.0-4+0~20230701.41+debian12~1.gbpbf7e27 amd64 +php8.1-imap 8.1.22-1+0~20230815.49+debian12~1.gbp8da143 amd64 +php8.1-intl 8.1.22-1+0~20230815.49+debian12~1.gbp8da143 amd64 +php8.1-mbstring 8.1.22-1+0~20230815.49+debian12~1.gbp8da143 amd64 -php8.1-memcached 3.2.0++-1+0~20230622.54+debian11~1.gbp8f3995 amd64 +php8.1-memcached 3.2.0++-1+0~20230622.54+debian12~1.gbp8f3995 amd64 -php8.1-mysql 8.1.22-1+0~20230815.49+debian11~1.gbp8da143 amd64 -php8.1-opcache 8.1.22-1+0~20230815.49+debian11~1.gbp8da143 amd64 -php8.1-readline 8.1.22-1+0~20230815.49+debian11~1.gbp8da143 amd64 -php8.1-redis 5.3.7++-1+0~20230619.51+debian11~1.gbp4ff337 amd64 -php8.1-xml 8.1.22-1+0~20230815.49+debian11~1.gbp8da143 amd64 -php8.1-zip 8.1.22-1+0~20230815.49+debian11~1.gbp8da143 amd64 -pinentry-curses 1.1.0-4 amd64 +php8.1-mysql 8.1.22-1+0~20230815.49+debian12~1.gbp8da143 amd64 +php8.1-opcache 8.1.22-1+0~20230815.49+debian12~1.gbp8da143 amd64 +php8.1-readline 8.1.22-1+0~20230815.49+debian12~1.gbp8da143 amd64 +php8.1-redis 5.3.7++-1+0~20230619.51+debian12~1.gbp4ff337 amd64 +php8.1-xml 8.1.22-1+0~20230815.49+debian12~1.gbp8da143 amd64 +php8.1-zip 8.1.22-1+0~20230815.49+debian12~1.gbp8da143 amd64 +pinentry-curses 1.2.1-1 amd64 +plocate 1.1.18-1 amd64 -postfix 3.5.18-0+deb11u1 amd64 -postfix-mysql 3.5.18-0+deb11u1 amd64 -postfix-pcre 3.5.18-0+deb11u1 amd64 -postfix-sqlite 3.5.18-0+deb11u1 amd64 +postfix 3.7.6-0+deb12u2 amd64 +postfix-mysql 3.7.6-0+deb12u2 amd64 +postfix-pcre 3.7.6-0+deb12u2 amd64 +postfix-sqlite 3.7.6-0+deb12u2 amd64 -procps 2:3.3.17-5 amd64 -psmisc 23.4-2 amd64 +procps 2:4.0.2-3 amd64 +psmisc 23.6-1 amd64 -pv 1.6.6-1+b1 amd64 +pv 1.6.20-1 amd64 +python-babel-localedata 2.10.3-1 all -python3 3.9.2-3 amd64 -python3-apt 2.2.1 amd64 +python3 3.11.2-1+b1 amd64 +python3-apt 2.6.0 amd64 +python3-babel 2.10.3-1 all -python3-cffi-backend 1.14.5-1 amd64 +python3-cffi-backend 1.15.1-5+b1 amd64 +python3-charset-normalizer 3.0.1-2 all -python3-cryptography 3.3.2-1 amd64 -python3-dbus 1.2.16-5 amd64 +python3-cryptography 38.0.4-3 amd64 +python3-dbus 1.3.2-4+b1 amd64 -python3-debian 0.1.39 all +python3-debian 0.1.49 all -python3-distutils 3.9.2-1 all -python3-gi 3.38.0-2 amd64 -python3-httplib2 0.18.1-3 all +python3-distutils 3.11.2-3 all +python3-gi 3.42.2-3+b1 amd64 +python3-httplib2 0.20.4-3 all -python3-jinja2 2.11.3-1 all +python3-jinja2 3.1.2-1 all -python3-jsonschema 3.2.0-3 all +python3-jsonschema 4.10.3-1 all -python3-lib2to3 3.9.2-1 all -python3-markupsafe 1.1.1-1+b3 amd64 -python3-minimal 3.9.2-3 amd64 +python3-lib2to3 3.11.2-3 all +python3-markupsafe 2.1.2-1+b1 amd64 +python3-minimal 3.11.2-1+b1 amd64 +python3-netifaces 0.11.0-2+b1 amd64 +python3-ntp 1.2.2+dfsg1-1+deb12u1 amd64 -python3-pycurl 7.43.0.6-5 amd64 +python3-pycurl 7.45.2-3 amd64 -python3-pyrsistent 0.15.5-1+b3 amd64 +python3-pyparsing 3.0.9-1 all +python3-pyrsistent 0.18.1-1+b3 amd64 -python3-requests 2.25.1+dfsg-2 all +python3-requests 2.28.1+dfsg-1 all +python3-rfc3987 1.3.8-2 all +python3-serial 3.5-1.1 all -python3-systemd 234-3+b4 amd64 +python3-systemd 235-1+b2 amd64 +python3-tz 2022.7.1-4 all +python3-uritemplate 4.1.1-2 all -python3-yaml 5.3.1-5 amd64 +python3-webcolors 1.11.1-1 all +python3-yaml 6.0-3+b2 amd64 +python3.11 3.11.2-6 amd64 +python3.11-minimal 3.11.2-6 amd64 -qemu-guest-agent 1:5.2+dfsg-11+deb11u2 amd64 +qemu-guest-agent 1:7.2+dfsg-7+deb12u1 amd64 -redis 5:6.0.16-1+deb11u2 all -redis-server 5:6.0.16-1+deb11u2 amd64 -redis-tools 5:6.0.16-1+deb11u2 amd64 +redis 5:7.0.11-1 all +redis-server 5:7.0.11-1 amd64 +redis-tools 5:7.0.11-1 amd64 -restic 0.11.0-1+b5 amd64 +restic 0.14.0-1+b5 amd64 +rpcsvc-proto 1.4.3-1 amd64 -rsync 3.2.3-4+deb11u1 amd64 -rsyslog 8.2102.0-2+deb11u1 amd64 -ruby 1:2.7+2 amd64 +rsync 3.2.7-1 amd64 +rsyslog 8.2302.0-1 amd64 +ruby 1:3.1 amd64 +ruby-sdbm 1.0.0-5+b1 amd64 +ruby-webrick 1.8.1-1 all +ruby3.1 3.1.2-7 amd64 -screen 4.8.0-6 amd64 -sed 4.7-1 amd64 +screen 4.9.0-4 amd64 +sed 4.9-1 amd64 -shared-mime-info 2.0-1 amd64 -sntp 1:4.2.8p15+dfsg-1 amd64 -socat 1.7.4.1-3 amd64 +sgml-base 1.31 all +shared-mime-info 2.2-1 amd64 +sntp 1:4.2.8p15+dfsg-2~1.2.2+dfsg1-1+deb12u1 all +socat 1.7.4.4-2 amd64 -strace 5.10-1 amd64 -sudo 1.9.5p2-3+deb11u1 amd64 -sysstat 12.5.2-2 amd64 -systemd 247.3-7+deb11u4 amd64 +strace 6.1-0.1 amd64 +sudo 1.9.13p3-1+deb12u1 amd64 +sysstat 12.6.1-1 amd64 +systemd 252.12-1~deb12u1 amd64 -sysvinit-utils 2.96-7+deb11u1 amd64 -tar 1.34+dfsg-1 amd64 +sysvinit-utils 3.06-4 amd64 +tar 1.34+dfsg-1.2 amd64 -telnet 0.17-42 amd64 -time 1.9-0.1 amd64 -traceroute 1:2.1.0-2+deb11u1 amd64 +telnet 0.17+2.4-2 all +time 1.9-0.2 amd64 +traceroute 1:2.1.2-1 amd64 -udev 247.3-7+deb11u4 amd64 +udev 252.12-1~deb12u1 amd64 -unbound 1.13.1-1+deb11u1 amd64 -unbound-anchor 1.13.1-1+deb11u1 amd64 -unhide 20130526-4 amd64 +unbound 1.17.1-2 amd64 +unbound-anchor 1.17.1-2 amd64 +unhide 20220611-1 amd64 -unzip 6.0-26+deb11u1 amd64 +unzip 6.0-28 amd64 -util-linux 2.36.1-8+deb11u1 amd64 -util-linux-locales 2.36.1-8+deb11u1 all -vim-common 2:8.2.2434-3+deb11u1 all -vim-tiny 2:8.2.2434-3+deb11u1 amd64 +usrmerge 35 all +util-linux 2.38.1-5+b1 amd64 +util-linux-extra 2.38.1-5+b1 amd64 +util-linux-locales 2.38.1-5 all +vim-common 2:9.0.1378-2 all +vim-tiny 2:9.0.1378-2 amd64 -wget 1.21-1+deb11u1 amd64 -whiptail 0.52.21-4+b3 amd64 -whois 5.5.10 amd64 -xauth 1:1.1-1 amd64 -xdg-user-dirs 0.17-2 amd64 +wget 1.21.3-1+b2 amd64 +whiptail 0.52.23-1+b1 amd64 +whois 5.5.17 amd64 +x11-common 1:7.7+23 all +xauth 1:1.1.2-1 amd64 +xdg-user-dirs 0.18-1 amd64 +xfonts-encodings 1:1.0.4-2.2 all +xfonts-utils 1:7.7+6 amd64 -xxd 2:8.2.2434-3+deb11u1 amd64 -xz-utils 5.2.5-2.1~deb11u1 amd64 +xxd 2:9.0.1378-2 amd64 +xz-utils 5.4.1-0.2 amd64 -zip 3.0-12 amd64 +zip 3.0-13 amd64 +zstd 1.5.4+dfsg2-5 amd64
This commit is contained in:
@@ -0,0 +1,78 @@
|
||||
query {label {multi_transaction {yes
|
||||
}
|
||||
data {yes
|
||||
}
|
||||
perms {allow deny audit quiet
|
||||
}
|
||||
}
|
||||
}
|
||||
dbus {mask {acquire send receive
|
||||
}
|
||||
}
|
||||
signal {mask {hup int quit ill trap abrt bus fpe kill usr1 segv usr2 pipe alrm term stkflt chld cont stop stp ttin ttou urg xcpu xfsz vtalrm prof winch io pwr sys emt lost
|
||||
}
|
||||
}
|
||||
ptrace {mask {read trace
|
||||
}
|
||||
}
|
||||
caps {mask {chown dac_override dac_read_search fowner fsetid kill setgid setuid setpcap linux_immutable net_bind_service net_broadcast net_admin net_raw ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap mac_override mac_admin syslog wake_alarm block_suspend audit_read perfmon bpf
|
||||
}
|
||||
}
|
||||
rlimit {mask {cpu fsize data stack core rss nproc nofile memlock as locks sigpending msgqueue nice rtprio rttime
|
||||
}
|
||||
}
|
||||
capability {0xffffff
|
||||
}
|
||||
namespaces {pivot_root {no
|
||||
}
|
||||
profile {yes
|
||||
}
|
||||
}
|
||||
mount {mask {mount umount pivot_root
|
||||
}
|
||||
}
|
||||
network {af_unix {yes
|
||||
}
|
||||
af_mask {unspec unix inet ax25 ipx appletalk netrom bridge atmpvc x25 inet6 rose netbeui security key netlink packet ash econet atmsvc rds sna irda pppox wanpipe llc ib mpls can tipc bluetooth iucv rxrpc isdn phonet ieee802154 caif alg nfc vsock kcm qipcrtr smc xdp
|
||||
}
|
||||
}
|
||||
network_v8 {af_mask {unspec unix inet ax25 ipx appletalk netrom bridge atmpvc x25 inet6 rose netbeui security key netlink packet ash econet atmsvc rds sna irda pppox wanpipe llc ib mpls can tipc bluetooth iucv rxrpc isdn phonet ieee802154 caif alg nfc vsock kcm qipcrtr smc xdp
|
||||
}
|
||||
}
|
||||
file {mask {create read write exec append mmap_exec link lock
|
||||
}
|
||||
}
|
||||
domain {version {1.2
|
||||
}
|
||||
attach_conditions {xattr {yes
|
||||
}
|
||||
}
|
||||
computed_longest_left {yes
|
||||
}
|
||||
post_nnp_subset {yes
|
||||
}
|
||||
fix_binfmt_elf_mmap {yes
|
||||
}
|
||||
stack {yes
|
||||
}
|
||||
change_profile {yes
|
||||
}
|
||||
change_onexec {yes
|
||||
}
|
||||
change_hatv {yes
|
||||
}
|
||||
change_hat {yes
|
||||
}
|
||||
}
|
||||
policy {set_load {yes
|
||||
}
|
||||
versions {v8 {yes
|
||||
}
|
||||
v7 {yes
|
||||
}
|
||||
v6 {yes
|
||||
}
|
||||
v5 {yes
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,76 @@
|
||||
query {label {multi_transaction {yes
|
||||
}
|
||||
data {yes
|
||||
}
|
||||
perms {allow deny audit quiet
|
||||
}
|
||||
}
|
||||
}
|
||||
dbus {mask {acquire send receive
|
||||
}
|
||||
}
|
||||
signal {mask {hup int quit ill trap abrt bus fpe kill usr1 segv usr2 pipe alrm term stkflt chld cont stop stp ttin ttou urg xcpu xfsz vtalrm prof winch io pwr sys emt lost
|
||||
}
|
||||
}
|
||||
ptrace {mask {read trace
|
||||
}
|
||||
}
|
||||
caps {mask {chown dac_override dac_read_search fowner fsetid kill setgid setuid setpcap linux_immutable net_bind_service net_broadcast net_admin net_raw ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap mac_override mac_admin syslog wake_alarm block_suspend audit_read
|
||||
}
|
||||
}
|
||||
rlimit {mask {cpu fsize data stack core rss nproc nofile memlock as locks sigpending msgqueue nice rtprio rttime
|
||||
}
|
||||
}
|
||||
capability {0xffffff
|
||||
}
|
||||
namespaces {pivot_root {no
|
||||
}
|
||||
profile {yes
|
||||
}
|
||||
}
|
||||
mount {mask {mount umount pivot_root
|
||||
}
|
||||
}
|
||||
network {af_unix {yes
|
||||
}
|
||||
af_mask {unspec unix inet ax25 ipx appletalk netrom bridge atmpvc x25 inet6 rose netbeui security key netlink packet ash econet atmsvc rds sna irda pppox wanpipe llc ib mpls can tipc bluetooth iucv rxrpc isdn phonet ieee802154 caif alg nfc vsock kcm qipcrtr smc xdp
|
||||
}
|
||||
}
|
||||
}
|
||||
file {mask {create read write exec append mmap_exec link lock
|
||||
}
|
||||
}
|
||||
domain {version {1.2
|
||||
}
|
||||
attach_conditions {xattr {yes
|
||||
}
|
||||
}
|
||||
computed_longest_left {yes
|
||||
}
|
||||
post_nnp_subset {yes
|
||||
}
|
||||
fix_binfmt_elf_mmap {yes
|
||||
}
|
||||
stack {yes
|
||||
}
|
||||
change_profile {yes
|
||||
}
|
||||
change_onexec {yes
|
||||
}
|
||||
change_hatv {yes
|
||||
}
|
||||
change_hat {yes
|
||||
}
|
||||
}
|
||||
policy {set_load {yes
|
||||
}
|
||||
versions {v8 {yes
|
||||
}
|
||||
v7 {yes
|
||||
}
|
||||
v6 {yes
|
||||
}
|
||||
v5 {yes
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,68 @@
|
||||
query {label {multi_transaction {yes
|
||||
}
|
||||
data {yes
|
||||
}
|
||||
perms {allow deny audit quiet
|
||||
}
|
||||
}
|
||||
}
|
||||
signal {mask {hup int quit ill trap abrt bus fpe kill usr1 segv usr2 pipe alrm term stkflt chld cont stop stp ttin ttou urg xcpu xfsz vtalrm prof winch io pwr sys emt lost
|
||||
}
|
||||
}
|
||||
ptrace {mask {read trace
|
||||
}
|
||||
}
|
||||
caps {mask {chown dac_override dac_read_search fowner fsetid kill setgid setuid setpcap linux_immutable net_bind_service net_broadcast net_admin net_raw ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap mac_override mac_admin syslog wake_alarm block_suspend audit_read
|
||||
}
|
||||
}
|
||||
rlimit {mask {cpu fsize data stack core rss nproc nofile memlock as locks sigpending msgqueue nice rtprio rttime
|
||||
}
|
||||
}
|
||||
capability {0xffffff
|
||||
}
|
||||
namespaces {pivot_root {no
|
||||
}
|
||||
profile {yes
|
||||
}
|
||||
}
|
||||
mount {mask {mount umount pivot_root
|
||||
}
|
||||
}
|
||||
}
|
||||
file {mask {create read write exec append mmap_exec link lock
|
||||
}
|
||||
}
|
||||
domain {version {1.2
|
||||
}
|
||||
attach_conditions {xattr {yes
|
||||
}
|
||||
}
|
||||
computed_longest_left {yes
|
||||
}
|
||||
post_nnp_subset {yes
|
||||
}
|
||||
fix_binfmt_elf_mmap {yes
|
||||
}
|
||||
stack {yes
|
||||
}
|
||||
change_profile {yes
|
||||
}
|
||||
change_onexec {yes
|
||||
}
|
||||
change_hatv {yes
|
||||
}
|
||||
change_hat {yes
|
||||
}
|
||||
}
|
||||
policy {set_load {yes
|
||||
}
|
||||
versions {v8 {yes
|
||||
}
|
||||
v7 {yes
|
||||
}
|
||||
v6 {yes
|
||||
}
|
||||
v5 {yes
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -10,7 +10,9 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
#include <abstractions/dri-common>
|
||||
abi <abi/3.0>,
|
||||
|
||||
include <abstractions/dri-common>
|
||||
|
||||
|
||||
# .ICEauthority files required for X authentication, per user
|
||||
@@ -20,12 +22,12 @@
|
||||
# .Xauthority files required for X connections, per user
|
||||
owner @{HOME}/.Xauthority r,
|
||||
owner @{HOME}/.local/share/sddm/.Xauthority r,
|
||||
owner /{,var/}run/gdm{,3}/*/database r,
|
||||
owner /{,var/}run/lightdm/authority/[0-9]* r,
|
||||
owner /{,var/}run/lightdm/*/xauthority r,
|
||||
owner /{,var/}run/user/*/gdm/Xauthority r,
|
||||
owner /{,var/}run/user/*/X11/Xauthority r,
|
||||
owner /{,var/}run/user/*/xauth_* r,
|
||||
owner @{run}/gdm{,3}/*/database r,
|
||||
owner @{run}/lightdm/authority/[0-9]* r,
|
||||
owner @{run}/lightdm/*/xauthority r,
|
||||
owner @{run}/user/*/gdm/Xauthority r,
|
||||
owner @{run}/user/*/X11/Xauthority r,
|
||||
owner @{run}/user/*/xauth_* r,
|
||||
|
||||
# the unix socket to use to connect to the display
|
||||
/tmp/.X11-unix/* rw,
|
||||
@@ -58,5 +60,7 @@
|
||||
/etc/X11/cursors/** r,
|
||||
|
||||
# Xwayland
|
||||
owner /run/user/*/.mutter-Xwaylandauth.* r,
|
||||
owner @{run}/user/*/.mutter-Xwaylandauth.* r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/X.d>
|
||||
|
||||
@@ -2,8 +2,14 @@
|
||||
|
||||
# This file contains basic permissions for Apache and every vHost
|
||||
|
||||
#include <abstractions/nameservice>
|
||||
abi <abi/3.0>,
|
||||
|
||||
include <abstractions/nameservice>
|
||||
|
||||
# Allow other processes to read our /proc entries
|
||||
ptrace (readby),
|
||||
# Allow other processes to trace us by default
|
||||
ptrace (tracedby),
|
||||
# Allow unconfined processes to send us signals by default
|
||||
signal (receive) peer=unconfined,
|
||||
# Allow apache to send us signals by default
|
||||
@@ -20,7 +26,7 @@
|
||||
/usr/share/apache2/** r,
|
||||
|
||||
# changehat itself
|
||||
@{PROC}/@{pid}/attr/current rw,
|
||||
@{PROC}/@{pid}/attr/{apparmor/,}current rw,
|
||||
|
||||
# htaccess files - for what ever it is worth
|
||||
/**/.htaccess r,
|
||||
@@ -28,7 +34,10 @@
|
||||
/dev/urandom r,
|
||||
|
||||
# sasl-auth
|
||||
/run/saslauthd/mux rw,
|
||||
@{run}/saslauthd/mux rw,
|
||||
|
||||
# OCSP stapling
|
||||
/var/log/apache2/stapling-cache rw,
|
||||
@{run}/lock/apache2/stapling-cache* rw,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/apache2-common.d>
|
||||
|
||||
@@ -6,6 +6,8 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
#include <abstractions/apparmor_api/introspect>
|
||||
abi <abi/3.0>,
|
||||
|
||||
@{PROC}/@{tid}/attr/{current,exec} w,
|
||||
include <abstractions/apparmor_api/introspect>
|
||||
|
||||
@{PROC}/@{tid}/attr/{apparmor/,}{current,exec} w,
|
||||
|
||||
@@ -9,4 +9,6 @@
|
||||
# Make sure to include at least tunables/proc and tunables/kernelvars
|
||||
# when using this abstraction, if not tunables/global.
|
||||
|
||||
@{PROC}/@{pids}/attr/{current,prev,exec} r,
|
||||
abi <abi/3.0>,
|
||||
|
||||
@{PROC}/@{pids}/attr/{apparmor/,}{current,prev,exec} r,
|
||||
|
||||
@@ -6,6 +6,8 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
#permissions needed for aa_find_mountpoint
|
||||
|
||||
# Make sure to include at least tunables/proc and tunables/kernelvars
|
||||
|
||||
@@ -6,7 +6,9 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# Make sure to include at least tunables/proc and tunables/kernelvars
|
||||
# when using this abstraction, if not tunables/global.
|
||||
|
||||
@{PROC}/@{tid}/attr/{current,prev,exec} r,
|
||||
@{PROC}/@{tid}/attr/{apparmor/,}{current,prev,exec} r,
|
||||
|
||||
@@ -6,12 +6,15 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# permissions needed for aa_is_enabled
|
||||
|
||||
# Make sure to include tunables/apparmorfs and tunables/global
|
||||
# when using this abstraction
|
||||
|
||||
#include <abstractions/apparmor_api/find_mountpoint>
|
||||
include <abstractions/apparmor_api/find_mountpoint>
|
||||
@{sys}/module/apparmor/parameters/enabled r,
|
||||
@{sys}/module/apparmor/parameters/available r,
|
||||
|
||||
# TODO: add alternate apparmorfs interface for enabled
|
||||
|
||||
@@ -1,6 +1,8 @@
|
||||
# vim:syntax=apparmor
|
||||
# aspell permissions
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# per-user settings and dictionaries
|
||||
owner @{HOME}/.aspell.*.{pws,prepl} rwk,
|
||||
|
||||
@@ -11,3 +13,6 @@
|
||||
/usr/share/aspell/ r,
|
||||
/usr/share/aspell/* r,
|
||||
/var/lib/aspell/* r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/aspell.d>
|
||||
|
||||
@@ -10,6 +10,7 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
|
||||
/dev/admmidi* rw,
|
||||
@@ -55,13 +56,15 @@ owner @{HOME}/.cache/event-sound-cache.* rwk,
|
||||
# pulse
|
||||
/etc/pulse/ r,
|
||||
/etc/pulse/** r,
|
||||
/{run,dev}/shm/ r,
|
||||
owner /{run,dev}/shm/pulse-shm* rwk,
|
||||
/dev/shm/ r,
|
||||
@{run}/shm/ r,
|
||||
owner /dev/shm/pulse-shm* rwk,
|
||||
owner @{run}/shm/pulse-shm* rwk,
|
||||
owner @{HOME}/.pulse-cookie rwk,
|
||||
owner @{HOME}/.pulse/ rw,
|
||||
owner @{HOME}/.pulse/* rwk,
|
||||
owner /{,var/}run/user/*/pulse/ rw,
|
||||
owner /{,var/}run/user/*/pulse/{native,pid} rwk,
|
||||
owner @{run}/user/*/pulse/ rw,
|
||||
owner @{run}/user/*/pulse/{native,pid} rwk,
|
||||
owner @{HOME}/.config/pulse/*.conf r,
|
||||
owner @{HOME}/.config/pulse/client.conf.d/{,*.conf} r,
|
||||
owner @{HOME}/.config/pulse/cookie rwk,
|
||||
@@ -81,3 +84,9 @@ owner @{HOME}/.local/share/openal/hrtf/{,**} r,
|
||||
|
||||
# wildmidi
|
||||
/etc/wildmidi/wildmidi.cfg r,
|
||||
|
||||
# pipewire
|
||||
/usr/share/pipewire/client.conf r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/audio.d>
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
#
|
||||
# Copyright (C) 2002-2009 Novell/SUSE
|
||||
# Copyright (C) 2009-2012 Canonical Ltd
|
||||
# Copyright (C) 2019 Christian Boltz
|
||||
# Copyright (C) 2019-2021 Christian Boltz
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or
|
||||
# modify it under the terms of version 2 of the GNU General Public
|
||||
@@ -10,18 +10,19 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
|
||||
# Some services need to perform authentication of users
|
||||
# Such authentication almost certainly needs access to the local users
|
||||
# databases containing passwords, PAM configuration files, PAM libraries
|
||||
/{usr/,}etc/nologin r,
|
||||
/{usr/,}etc/pam.d/* r,
|
||||
/{usr/,}etc/securetty r,
|
||||
/{usr/,}etc/security/* r,
|
||||
/{usr/,}etc/shadow r,
|
||||
/{usr/,}etc/gshadow r,
|
||||
/{usr/,}etc/pwdb.conf r,
|
||||
@{etc_ro}/nologin r,
|
||||
@{etc_ro}/pam.d/* r,
|
||||
@{etc_ro}/securetty r,
|
||||
@{etc_ro}/security/* r,
|
||||
@{etc_ro}/shadow r,
|
||||
@{etc_ro}/gshadow r,
|
||||
@{etc_ro}/pwdb.conf r,
|
||||
|
||||
/{usr/,}lib{,32,64}/security/pam_filter/* mr,
|
||||
/{usr/,}lib{,32,64}/security/pam_*.so mr,
|
||||
@@ -31,22 +32,27 @@
|
||||
/{usr/,}lib/@{multiarch}/security/ r,
|
||||
|
||||
# kerberos
|
||||
#include <abstractions/kerberosclient>
|
||||
include <abstractions/kerberosclient>
|
||||
# SuSE's pwdutils are different:
|
||||
/{usr/,}etc/default/passwd r,
|
||||
/{usr/,}etc/login.defs r,
|
||||
@{etc_ro}/default/passwd r,
|
||||
@{etc_ro}/login.defs r,
|
||||
@{etc_ro}/login.defs.d/ r,
|
||||
@{etc_ro}/login.defs.d/*.defs r,
|
||||
|
||||
# nis
|
||||
#include <abstractions/nis>
|
||||
include <abstractions/nis>
|
||||
|
||||
# winbind
|
||||
#include <abstractions/winbind>
|
||||
include <abstractions/winbind>
|
||||
|
||||
# likewise
|
||||
#include <abstractions/likewise>
|
||||
include <abstractions/likewise>
|
||||
|
||||
# smbpass
|
||||
#include <abstractions/smbpass>
|
||||
include <abstractions/smbpass>
|
||||
|
||||
# p11-kit (PKCS#11 modules configuration)
|
||||
#include <abstractions/p11-kit>
|
||||
include <abstractions/p11-kit>
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/authentication.d>
|
||||
|
||||
@@ -10,7 +10,9 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
include <abstractions/crypto>
|
||||
|
||||
# (Note that the ldd profile has inlined this file; if you make
|
||||
# modifications here, please consider including them in the ldd
|
||||
@@ -26,10 +28,10 @@
|
||||
# Allow access to the uuidd daemon (this daemon is a thin wrapper around
|
||||
# time and getrandom()/{,u}random and, when available, runs under an
|
||||
# unprivilged, dedicated user).
|
||||
/run/uuidd/request r,
|
||||
/etc/locale/** r,
|
||||
/etc/locale.alias r,
|
||||
/etc/localtime r,
|
||||
@{run}/uuidd/request r,
|
||||
@{etc_ro}/locale/** r,
|
||||
@{etc_ro}/locale.alias r,
|
||||
@{etc_ro}/localtime r,
|
||||
/etc/writable/localtime r,
|
||||
/usr/share/locale-bundle/** r,
|
||||
/usr/share/locale-langpack/** r,
|
||||
@@ -38,13 +40,13 @@
|
||||
/usr/share/zoneinfo/ r,
|
||||
/usr/share/zoneinfo/** r,
|
||||
/usr/share/X11/locale/** r,
|
||||
/run/systemd/journal/dev-log w,
|
||||
@{run}/systemd/journal/dev-log w,
|
||||
# systemd native journal API (see sd_journal_print(4))
|
||||
/run/systemd/journal/socket w,
|
||||
@{run}/systemd/journal/socket w,
|
||||
# Nested containers and anything using systemd-cat need this. 'r' shouldn't
|
||||
# be required but applications fail without it. journald doesn't leak
|
||||
# anything when reading so this is ok.
|
||||
/run/systemd/journal/stdout rw,
|
||||
@{run}/systemd/journal/stdout rw,
|
||||
|
||||
/usr/lib{,32,64}/locale/** mr,
|
||||
/usr/lib{,32,64}/gconv/*.so mr,
|
||||
@@ -53,14 +55,14 @@
|
||||
/usr/lib/@{multiarch}/gconv/gconv-modules* mr,
|
||||
|
||||
# used by glibc when binding to ephemeral ports
|
||||
/etc/bindresvport.blacklist r,
|
||||
@{etc_ro}/bindresvport.blacklist r,
|
||||
|
||||
# ld.so.cache and ld are used to load shared libraries; they are best
|
||||
# available everywhere
|
||||
/etc/ld.so.cache mr,
|
||||
/etc/ld.so.conf r,
|
||||
/etc/ld.so.conf.d/{,*.conf} r,
|
||||
/etc/ld.so.preload r,
|
||||
@{etc_ro}/ld.so.cache mr,
|
||||
@{etc_ro}/ld.so.conf r,
|
||||
@{etc_ro}/ld.so.conf.d/{,*.conf} r,
|
||||
@{etc_ro}/ld.so.preload r,
|
||||
/{usr/,}lib{,32,64}/ld{,32,64}-*.so mr,
|
||||
/{usr/,}lib/@{multiarch}/ld{,32,64}-*.so mr,
|
||||
/{usr/,}lib/tls/i686/{cmov,nosegneg}/ld-*.so mr,
|
||||
@@ -75,6 +77,11 @@
|
||||
/{usr/,}lib/tls/i686/{cmov,nosegneg}/*.so* mr,
|
||||
/{usr/,}lib/i386-linux-gnu/tls/i686/{cmov,nosegneg}/*.so* mr,
|
||||
|
||||
# FIPS-140-2 versions of some crypto libraries need to access their
|
||||
# associated integrity verification file, or they will abort.
|
||||
/{usr/,}lib{,32,64}/.lib*.so*.hmac r,
|
||||
/{usr/,}lib/@{multiarch}/.lib*.so*.hmac r,
|
||||
|
||||
# /dev/null is pretty harmless and frequently used
|
||||
/dev/null rw,
|
||||
# as is /dev/zero
|
||||
@@ -95,6 +102,7 @@
|
||||
@{PROC}/cpuinfo r,
|
||||
@{sys}/devices/system/cpu/ r,
|
||||
@{sys}/devices/system/cpu/online r,
|
||||
@{sys}/devices/system/cpu/possible r,
|
||||
|
||||
# glibc's *printf protections read the maps file
|
||||
@{PROC}/@{pid}/{maps,auxv,status} r,
|
||||
@@ -166,3 +174,6 @@
|
||||
owner @{HOMEDIRS}/.ecryptfs/*/.Private/ r,
|
||||
owner @{HOMEDIRS}/.ecryptfs/*/.Private/** mrixwlk,
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/base.d>
|
||||
|
||||
@@ -8,6 +8,8 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# user-specific bash files
|
||||
@{HOMEDIRS} r,
|
||||
@{HOME}/.bashrc r,
|
||||
@@ -42,3 +44,6 @@
|
||||
/etc/DIR_COLORS r,
|
||||
/{usr/,}bin/ls mix,
|
||||
/usr/bin/dircolors mix,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/bash.d>
|
||||
|
||||
@@ -9,6 +9,7 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
|
||||
# there are three common ways to refer to consoles
|
||||
@@ -21,3 +22,6 @@
|
||||
/dev/pts/[0-9]* rw,
|
||||
/dev/pts/ r,
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/consoles.d>
|
||||
|
||||
@@ -0,0 +1,27 @@
|
||||
# vim:syntax=apparmor
|
||||
# ------------------------------------------------------------------
|
||||
#
|
||||
# Copyright (C) 2002-2009 Novell/SUSE
|
||||
# Copyright (C) 2009-2011 Canonical Ltd.
|
||||
# Copyright (C) 2021 Christian Boltz
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or
|
||||
# modify it under the terms of version 2 of the GNU General Public
|
||||
# License published by the Free Software Foundation.
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
@{etc_ro}/gcrypt/hwf.deny r,
|
||||
@{etc_ro}/gcrypt/random.conf r,
|
||||
@{PROC}/sys/crypto/fips_enabled r,
|
||||
|
||||
# libgcrypt reads some flags from /proc
|
||||
@{PROC}/sys/crypto/* r,
|
||||
|
||||
# crypto policies used by various libraries
|
||||
/etc/crypto-policies/*/*.txt r,
|
||||
/usr/share/crypto-policies/*/*.txt r,
|
||||
|
||||
include if exists <abstractions/crypto.d>
|
||||
@@ -9,10 +9,15 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# discoverable system configuration for non-local cupsd
|
||||
/etc/cups/client.conf r,
|
||||
# client should be able to talk the local cupsd
|
||||
/{,var/}run/cups/cups.sock rw,
|
||||
@{run}/cups/cups.sock rw,
|
||||
# client should be able to read user-specified cups configuration
|
||||
owner @{HOME}/.cups/client.conf r,
|
||||
owner @{HOME}/.cups/lpoptions r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/cups-client.d>
|
||||
|
||||
@@ -9,8 +9,13 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# This abstraction grants full system bus access. Consider using the
|
||||
# dbus-strict abstraction for fine-grained bus mediation.
|
||||
|
||||
#include <abstractions/dbus-strict>
|
||||
include <abstractions/dbus-strict>
|
||||
dbus bus=system,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/dbus.d>
|
||||
|
||||
@@ -9,8 +9,13 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# This abstraction grants full accessibility bus access. Consider using the
|
||||
# dbus-accessibility-strict abstraction for fine-grained bus mediation.
|
||||
|
||||
#include <abstractions/dbus-accessibility-strict>
|
||||
include <abstractions/dbus-accessibility-strict>
|
||||
dbus bus=accessibility,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/dbus-accessibility.d>
|
||||
|
||||
@@ -9,9 +9,14 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
dbus send
|
||||
bus=accessibility
|
||||
path=/org/freedesktop/DBus
|
||||
interface=org.freedesktop.DBus
|
||||
member={Hello,AddMatch,RemoveMatch,GetNameOwner,NameHasOwner,StartServiceByName}
|
||||
peer=(name=org.freedesktop.DBus),
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/dbus-accessibility-strict.d>
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
dbus send
|
||||
bus=system
|
||||
path=/org/freedesktop/NetworkManager
|
||||
@@ -42,4 +44,4 @@
|
||||
member=GetSettings
|
||||
peer=(name=org.freedesktop.NetworkManager),
|
||||
|
||||
#include if exists <abstractions/dbus-network-manager-strict.d>
|
||||
include if exists <abstractions/dbus-network-manager-strict.d>
|
||||
|
||||
@@ -9,9 +9,14 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# This abstraction grants full session bus access. Consider using the
|
||||
# dbus-session-strict abstraction for fine-grained bus mediation.
|
||||
|
||||
#include <abstractions/dbus-session-strict>
|
||||
include <abstractions/dbus-session-strict>
|
||||
/usr/bin/dbus-launch ix,
|
||||
dbus bus=session,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/dbus-session.d>
|
||||
|
||||
@@ -9,17 +9,18 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# unique per-machine identifier
|
||||
/etc/machine-id r,
|
||||
/var/lib/dbus/machine-id r,
|
||||
owner /run/user/*/bus rw,
|
||||
|
||||
unix (connect, receive, send)
|
||||
type=stream
|
||||
peer=(addr="@/tmp/dbus-*"),
|
||||
|
||||
# dbus with systemd and --enable-user-session
|
||||
owner /run/user/[0-9]*/bus rw,
|
||||
owner @{run}/user/[0-9]*/bus rw,
|
||||
|
||||
dbus send
|
||||
bus=session
|
||||
@@ -27,3 +28,6 @@
|
||||
interface=org.freedesktop.DBus
|
||||
member={Hello,AddMatch,RemoveMatch,GetNameOwner,NameHasOwner,StartServiceByName}
|
||||
peer=(name=org.freedesktop.DBus),
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/dbus-session-strict.d>
|
||||
|
||||
@@ -9,7 +9,9 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
/{,var/}run/dbus/system_bus_socket rw,
|
||||
abi <abi/3.0>,
|
||||
|
||||
@{run}/dbus/system_bus_socket rw,
|
||||
|
||||
dbus send
|
||||
bus=system
|
||||
@@ -17,3 +19,6 @@
|
||||
interface=org.freedesktop.DBus
|
||||
member={Hello,AddMatch,RemoveMatch,GetNameOwner,NameHasOwner,StartServiceByName}
|
||||
peer=(name=org.freedesktop.DBus),
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/dbus-strict.d>
|
||||
|
||||
@@ -1,8 +1,13 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# permissions for querying dconf settings; granting write access should
|
||||
# be specified in a specific application's profile.
|
||||
|
||||
/etc/dconf/** r,
|
||||
owner /{,var/}run/user/*/dconf/user r,
|
||||
owner @{run}/user/*/dconf/user r,
|
||||
owner @{HOME}/.config/dconf/user r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/dconf.d>
|
||||
|
||||
@@ -9,6 +9,8 @@
|
||||
# ------------------------------------------------------------------
|
||||
# used with dovecot/*
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
capability setgid,
|
||||
|
||||
deny capability block_suspend,
|
||||
@@ -16,4 +18,7 @@
|
||||
# dovecot's master can send us signals
|
||||
signal receive peer=dovecot,
|
||||
|
||||
/{var/,}run/dovecot/config rw,
|
||||
owner @{run}/dovecot/config rw,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/dovecot-common.d>
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# This file contains common DRI-specific rules useful for GUI applications
|
||||
# (needed by libdrm and similar).
|
||||
|
||||
@@ -12,3 +14,6 @@
|
||||
/usr/share/drirc.d/{,*.conf} r,
|
||||
owner @{HOME}/.drirc r,
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/dri-common.d>
|
||||
|
||||
@@ -1,8 +1,13 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# This file contains common DRI-specific rules useful for GUI applications that
|
||||
# needs to enumerate graphic devices (as with drmParsePciDeviceInfo() from
|
||||
# libdrm).
|
||||
|
||||
@{sys}/devices/pci[0-9]*/**/{device,subsystem_device,subsystem_vendor,uevent,vendor} r,
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/dri-enumerate.d>
|
||||
|
||||
@@ -9,6 +9,8 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# abstraction for Enchant spellchecking frontend
|
||||
|
||||
/usr/share/enchant/ r,
|
||||
@@ -18,7 +20,7 @@
|
||||
/usr/share/enchant-2/enchant.ordering r,
|
||||
|
||||
# aspell
|
||||
#include <abstractions/aspell>
|
||||
include <abstractions/aspell>
|
||||
/var/lib/dictionaries-common/aspell/ r,
|
||||
/var/lib/dictionaries-common/aspell/* r,
|
||||
|
||||
@@ -57,3 +59,6 @@
|
||||
# per-user dictionaries
|
||||
owner @{HOME}/.config/enchant/ rw,
|
||||
owner @{HOME}/.config/enchant/* rwk,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/enchant.d>
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# This abstraction is designed to be used in a child profile to limit what
|
||||
# confined application can invoke via exo-open helper.
|
||||
#
|
||||
@@ -18,27 +20,27 @@
|
||||
#
|
||||
# # out-of-line child profile
|
||||
# profile foo//exo-open {
|
||||
# #include <abstractions/exo-open>
|
||||
# include <abstractions/exo-open>
|
||||
#
|
||||
# # needed for ubuntu-* abstractions
|
||||
# #include <abstractions/ubuntu-helpers>
|
||||
# include <abstractions/ubuntu-helpers>
|
||||
#
|
||||
# # Only allow to handle http[s]: and mailto: links
|
||||
# #include <abstractions/ubuntu-browsers>
|
||||
# #include <abstractions/ubuntu-email>
|
||||
# include <abstractions/ubuntu-browsers>
|
||||
# include <abstractions/ubuntu-email>
|
||||
#
|
||||
# # Add if accesibility access is considered as required
|
||||
# # (for message boxe in case exo-open fails)
|
||||
# #include <abstractions/dbus-accessibility>
|
||||
# include <abstractions/dbus-accessibility>
|
||||
#
|
||||
# # < add additional allowed applications here >
|
||||
# }
|
||||
|
||||
#include <abstractions/X>
|
||||
#include <abstractions/audio> # for alert messages
|
||||
#include <abstractions/base>
|
||||
#include <abstractions/dbus-session-strict>
|
||||
#include <abstractions/gnome>
|
||||
include <abstractions/X>
|
||||
include <abstractions/audio> # for alert messages
|
||||
include <abstractions/base>
|
||||
include <abstractions/dbus-session-strict>
|
||||
include <abstractions/gnome>
|
||||
|
||||
# Main executables
|
||||
|
||||
@@ -49,13 +51,6 @@
|
||||
|
||||
/{,usr/}bin/which rix,
|
||||
|
||||
# Deny DBus
|
||||
|
||||
# for GTK error message dialog, not required exo-open to work.
|
||||
deny dbus send
|
||||
bus=session
|
||||
path=/org/gtk/vfs/mounttracker,
|
||||
|
||||
# System files
|
||||
|
||||
/etc/xdg/{,xdg-*/}xfce4/helpers.rc r,
|
||||
@@ -71,4 +66,4 @@
|
||||
owner @{HOME}/.local/share/xfce4/helpers/*.desktop r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
#include if exists <abstractions/exo-open.d>
|
||||
include if exists <abstractions/exo-open.d>
|
||||
|
||||
@@ -9,5 +9,10 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
#include <abstractions/fcitx-strict>
|
||||
abi <abi/3.0>,
|
||||
|
||||
include <abstractions/fcitx-strict>
|
||||
dbus bus=fcitx,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/fcitx.d>
|
||||
|
||||
@@ -9,7 +9,9 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
#include <abstractions/dbus-session-strict>
|
||||
abi <abi/3.0>,
|
||||
|
||||
include <abstractions/dbus-session-strict>
|
||||
|
||||
dbus send
|
||||
bus=fcitx
|
||||
@@ -19,3 +21,6 @@
|
||||
peer=(name=org.freedesktop.DBus),
|
||||
|
||||
owner @{HOME}/.config/fcitx/dbus/* r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/fcitx-strict.d>
|
||||
|
||||
@@ -10,6 +10,8 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
/usr/share/AbiSuite/fonts/** r,
|
||||
|
||||
/usr/lib/xorg/modules/fonts/**.so* mr,
|
||||
@@ -50,6 +52,8 @@
|
||||
owner @{HOME}/.fonts.conf.d/** r,
|
||||
owner @{HOME}/.config/fontconfig/ r,
|
||||
owner @{HOME}/.config/fontconfig/** r,
|
||||
owner @{HOME}/.Fontmatrix/Activated/ r,
|
||||
owner @{HOME}/.Fontmatrix/Activated/** r,
|
||||
|
||||
/usr/local/share/fonts/ r,
|
||||
/usr/local/share/fonts/** r,
|
||||
@@ -59,3 +63,6 @@
|
||||
|
||||
# data files for LibThai
|
||||
/usr/share/libthai/thbrk.tri r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/fonts.d>
|
||||
|
||||
@@ -9,6 +9,8 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# system configuration
|
||||
@{system_share_dirs}/applications/{**,} r,
|
||||
@{system_share_dirs}/icons/{**,} r,
|
||||
@@ -26,3 +28,6 @@
|
||||
owner @{user_share_dirs}/applications/{**,} r,
|
||||
owner @{user_share_dirs}/icons/{**,} r,
|
||||
owner @{user_share_dirs}/mime/{**,} r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/freedesktop.org.d>
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# This abstraction is designed to be used in a child profile to limit what
|
||||
# confined application can invoke via gio helper.
|
||||
#
|
||||
@@ -18,20 +20,20 @@
|
||||
#
|
||||
# # out-of-line child profile
|
||||
# profile foo//gio-open {
|
||||
# #include <abstractions/gio-open>
|
||||
# include <abstractions/gio-open>
|
||||
#
|
||||
# # needed for ubuntu-* abstractions
|
||||
# #include <abstractions/ubuntu-helpers>
|
||||
# include <abstractions/ubuntu-helpers>
|
||||
#
|
||||
# # Only allow to handle http[s]: and mailto: links
|
||||
# #include <abstractions/ubuntu-browsers>
|
||||
# #include <abstractions/ubuntu-email>
|
||||
# include <abstractions/ubuntu-browsers>
|
||||
# include <abstractions/ubuntu-email>
|
||||
#
|
||||
# # < add additional allowed applications here >
|
||||
# }
|
||||
|
||||
#include <abstractions/base>
|
||||
#include <abstractions/dbus-session-strict>
|
||||
include <abstractions/base>
|
||||
include <abstractions/dbus-session-strict>
|
||||
|
||||
# Main executables
|
||||
|
||||
@@ -54,4 +56,4 @@
|
||||
owner @{PROC}/@{pid}/fd/ r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
#include if exists <abstractions/gio-open.d>
|
||||
include if exists <abstractions/gio-open.d>
|
||||
|
||||
@@ -9,13 +9,16 @@
|
||||
# License published by the Free Software Foundation.
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
#include <abstractions/base>
|
||||
#include <abstractions/fonts>
|
||||
#include <abstractions/X>
|
||||
#include <abstractions/freedesktop.org>
|
||||
#include <abstractions/xdg-desktop>
|
||||
#include <abstractions/user-tmp>
|
||||
#include <abstractions/wayland>
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
include <abstractions/base>
|
||||
include <abstractions/fonts>
|
||||
include <abstractions/X>
|
||||
include <abstractions/freedesktop.org>
|
||||
include <abstractions/xdg-desktop>
|
||||
include <abstractions/user-tmp>
|
||||
include <abstractions/wayland>
|
||||
|
||||
# systemwide gtk defaults
|
||||
/etc/gnome/gtkrc* r,
|
||||
@@ -88,7 +91,7 @@
|
||||
/usr/share/gvfs/remote-volume-monitors/ r,
|
||||
/usr/share/gvfs/remote-volume-monitors/* r,
|
||||
@{PROC}/@{pid}/mounts r,
|
||||
/run/mount/utab r,
|
||||
@{run}/mount/utab r,
|
||||
|
||||
# printing
|
||||
/etc/papersize r,
|
||||
@@ -96,7 +99,7 @@
|
||||
/usr/share/cups/charmaps/** r,
|
||||
|
||||
# holds MIT-MAGIC-COOKIE for gnome
|
||||
owner /{,var/}run/gdm/auth*/database r,
|
||||
owner @{run}/gdm/auth*/database r,
|
||||
|
||||
# mime-types
|
||||
/etc/gnome/defaults.list r,
|
||||
@@ -109,3 +112,6 @@
|
||||
unix (send, receive, connect)
|
||||
type=stream
|
||||
peer=(addr="@/dbus-vfs-daemon/socket-*"),
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/gnome.d>
|
||||
|
||||
@@ -1,6 +1,8 @@
|
||||
# vim:syntax=apparmor
|
||||
# gnupg sub-process running permissions
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# user configurations
|
||||
owner @{HOME}/.gnupg/options r,
|
||||
owner @{HOME}/.gnupg/pubring.gpg r,
|
||||
@@ -9,3 +11,6 @@
|
||||
owner @{HOME}/.gnupg/secring.gpg r,
|
||||
owner @{HOME}/.gnupg/so/*.x86_64 mr,
|
||||
owner @{HOME}/.gnupg/trustdb.gpg rw,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/gnupg.d>
|
||||
|
||||
@@ -0,0 +1,55 @@
|
||||
# vim:syntax=apparmor
|
||||
# ------------------------------------------------------------------
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or
|
||||
# modify it under the terms of version 2 of the GNU General Public
|
||||
# License published by the Free Software Foundation.
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
/usr/share/themes/{,**} r,
|
||||
|
||||
/usr/share/gtksourceview-[0-9]*/{,**} r,
|
||||
|
||||
/usr/share/gtk-2.0/ r,
|
||||
/usr/share/gtk-2.0/gtkrc r,
|
||||
|
||||
/usr/share/gtk-{3,4}.0/ r,
|
||||
/usr/share/gtk-{3,4}.0/settings.ini r,
|
||||
|
||||
/etc/gtk-2.0/ r,
|
||||
/etc/gtk-2.0/gtkrc r,
|
||||
|
||||
/etc/gtk-{3,4}.0/ r,
|
||||
/etc/gtk-{3,4}.0/*.conf r,
|
||||
|
||||
/etc/gtk/gtkrc r,
|
||||
|
||||
owner @{HOME}/.themes/{,**} r,
|
||||
owner @{HOME}/.local/share/themes/{,**} r,
|
||||
|
||||
owner @{HOME}/.gtk r,
|
||||
owner @{HOME}/.gtkrc r,
|
||||
owner @{HOME}/.gtkrc-2.0 r,
|
||||
owner @{HOME}/.gtk-bookmarks r,
|
||||
owner @{HOME}/.config/gtkrc r,
|
||||
owner @{HOME}/.config/gtkrc-2.0 r,
|
||||
owner @{HOME}/.config/gtk-{3,4}.0/ rw,
|
||||
owner @{HOME}/.config/gtk-{3,4}.0/settings.ini r,
|
||||
owner @{HOME}/.config/gtk-{3,4}.0/bookmarks r,
|
||||
owner @{HOME}/.config/gtk-{3,4}.0/gtk.css r,
|
||||
|
||||
# for gtk file dialog
|
||||
owner @{HOME}/.config/gtk-2.0/ rw,
|
||||
owner @{HOME}/.config/gtk-2.0/gtkfilechooser.ini* rw,
|
||||
|
||||
# .Xauthority file required for X connections
|
||||
owner @{HOME}/.Xauthority r,
|
||||
|
||||
# Xsession errors file
|
||||
owner @{HOME}/.xsession-errors w,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/gtk.d>
|
||||
@@ -1,5 +1,7 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# This abstraction is designed to be used in a child profile to limit what
|
||||
# confined application can invoke via gvfs-open helper.
|
||||
#
|
||||
@@ -18,23 +20,23 @@
|
||||
#
|
||||
# # out-of-line child profile
|
||||
# profile foo//gvfs-open {
|
||||
# #include <abstractions/gvfs-open>
|
||||
# include <abstractions/gvfs-open>
|
||||
#
|
||||
# # needed for ubuntu-* abstractions
|
||||
# #include <abstractions/ubuntu-helpers>
|
||||
# include <abstractions/ubuntu-helpers>
|
||||
#
|
||||
# # Only allow to handle http[s]: and mailto: links
|
||||
# #include <abstractions/ubuntu-browsers>
|
||||
# #include <abstractions/ubuntu-email>
|
||||
# include <abstractions/ubuntu-browsers>
|
||||
# include <abstractions/ubuntu-email>
|
||||
#
|
||||
# # < add additional allowed applications here >
|
||||
# }
|
||||
# ```
|
||||
|
||||
#include <abstractions/base>
|
||||
include <abstractions/base>
|
||||
|
||||
# gvfs-open is deprecated, it launches gio open <uri>
|
||||
#include <abstractions/gio-open>
|
||||
include <abstractions/gio-open>
|
||||
|
||||
# Main executables
|
||||
|
||||
@@ -42,4 +44,4 @@
|
||||
/{,usr/}bin/dash mr,
|
||||
|
||||
# Include additions to the abstraction
|
||||
#include if exists <abstractions/gvfs-open.d>
|
||||
include if exists <abstractions/gvfs-open.d>
|
||||
|
||||
@@ -9,5 +9,9 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
/etc/hosts.deny r,
|
||||
/etc/hosts.allow r,
|
||||
|
||||
include if exists <abstractions/hosts_access.d>
|
||||
|
||||
@@ -9,16 +9,13 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# abstraction for ibus input methods
|
||||
owner @{HOME}/.config/ibus/ r,
|
||||
owner @{HOME}/.config/ibus/bus/ rw,
|
||||
owner @{HOME}/.config/ibus/bus/* rw,
|
||||
|
||||
# abstract path in ibus < 1.5.22 uses /tmp
|
||||
unix (connect, receive, send)
|
||||
type=stream
|
||||
peer=(addr="@/tmp/ibus/dbus-*"),
|
||||
|
||||
# abstract path in ibus >= 1.5.22 uses $XDG_CACHE_HOME (ie, @{HOME}/.cache)
|
||||
# This should use this, but due to LP: #1856738 we cannot
|
||||
#unix (connect, receive, send)
|
||||
@@ -27,3 +24,6 @@
|
||||
unix (connect, receive, send)
|
||||
type=stream
|
||||
peer=(addr="@/home/*/.cache/ibus/dbus-*"),
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/ibus.d>
|
||||
|
||||
@@ -9,13 +9,15 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
#include <abstractions/base>
|
||||
#include <abstractions/fonts>
|
||||
#include <abstractions/X>
|
||||
#include <abstractions/freedesktop.org>
|
||||
#include <abstractions/xdg-desktop>
|
||||
#include <abstractions/user-tmp>
|
||||
#include <abstractions/qt5>
|
||||
abi <abi/3.0>,
|
||||
|
||||
include <abstractions/base>
|
||||
include <abstractions/fonts>
|
||||
include <abstractions/X>
|
||||
include <abstractions/freedesktop.org>
|
||||
include <abstractions/xdg-desktop>
|
||||
include <abstractions/user-tmp>
|
||||
include <abstractions/qt5>
|
||||
|
||||
/etc/qt3/kstylerc r,
|
||||
/etc/qt3/qt_plugins_3.3rc r,
|
||||
@@ -39,8 +41,11 @@ owner @{HOME}/.config/Trolltech.conf rwk,
|
||||
owner @{HOME}/.config/baloofilerc r, # indexing options (excludes, etc), used by KFileWidget
|
||||
owner @{HOME}/.config/dolphinrc r, # settings used by KFileWidget
|
||||
owner @{HOME}/.config/kde.org/libphonon.conf r, # for KNotifications::sendEvent()
|
||||
owner @{HOME}/.config/kdedefaults/kdeglobals r, # QPlatformThemeFactory::create() -> KDEPlasmaPlatformTheme.so
|
||||
owner @{HOME}/.config/kdedefaults/kwinrc r, # QStyleFactory::create() -> qt5/plugins/styles/breeze.so
|
||||
owner @{HOME}/.config/kdeglobals r, # global settings, used by Breeze style, etc.
|
||||
owner @{HOME}/.config/klanguageoverridesrc r, # per-application languages, for KDEPrivate::initializeLanguages() from libKF5XmlGui.so
|
||||
owner @{HOME}/.config/kwinrc r, # QStyleFactory::create() -> qt5/plugins/styles/breeze.so
|
||||
owner @{HOME}/.config/trashrc r, # Used by KFileWidget
|
||||
|
||||
/usr/share/X11/XKeysymDB r,
|
||||
@@ -75,3 +80,6 @@ owner @{HOME}/.config/trashrc r, # Used by KFileWidget
|
||||
/usr/lib/@{multiarch}/qt4/lib*/lib*so* mr,
|
||||
/usr/lib/@{multiarch}/qt4/plugins/** mr,
|
||||
/usr/share/qt4/** r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/kde.d>
|
||||
|
||||
@@ -1,6 +1,8 @@
|
||||
# vim:syntax=apparmor
|
||||
# Rules for changing KDE settings (for KFileDialog and other).
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# User files
|
||||
|
||||
owner @{HOME}/.config/#[0-9]* rw,
|
||||
@@ -8,3 +10,6 @@
|
||||
owner @{HOME}/.config/kdeglobals.?????? rwl -> @{HOME}/.config/#[0-9]*,
|
||||
owner @{HOME}/.config/kdeglobals.lock rwk,
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/kde-globals-write.d>
|
||||
|
||||
@@ -1,7 +1,12 @@
|
||||
# vim:syntax=apparmor
|
||||
# Rules for writing KDE icon cache
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# User files
|
||||
|
||||
owner @{HOME}/.cache/icon-cache.kcache rw, # for KIconLoader
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/kde-icon-cache-write.d>
|
||||
|
||||
@@ -1,4 +1,7 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# Rules for changing per-application language settings on KDE. Some KDE
|
||||
# applications have "Help -> Switch Application Language..." option, that needs
|
||||
# write access to language settings file.
|
||||
@@ -10,3 +13,6 @@
|
||||
owner @{HOME}/.config/klanguageoverridesrc.?????? rwl -> @{HOME}/.config/#[0-9]*,
|
||||
owner @{HOME}/.config/klanguageoverridesrc.lock rwk,
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/kde-language-write.d>
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# This abstraction is designed to be used in a child profile to limit what
|
||||
# confined application can invoke via kde-open5 helper.
|
||||
#
|
||||
@@ -18,40 +20,40 @@
|
||||
#
|
||||
# # out-of-line child profile
|
||||
# profile foo//kde-open5 {
|
||||
# #include <abstractions/kde-open5>
|
||||
# include <abstractions/kde-open5>
|
||||
#
|
||||
# # needed for ubuntu-* abstractions
|
||||
# #include <abstractions/ubuntu-helpers>
|
||||
# include <abstractions/ubuntu-helpers>
|
||||
#
|
||||
# # Only allow to handle http[s]: and mailto: links
|
||||
# #include <abstractions/ubuntu-browsers>
|
||||
# #include <abstractions/ubuntu-email>
|
||||
# include <abstractions/ubuntu-browsers>
|
||||
# include <abstractions/ubuntu-email>
|
||||
#
|
||||
# # Add if accesibility access is considered as required
|
||||
# # (for message boxe in case exo-open fails)
|
||||
# #include <abstractions/dbus-accessibility>
|
||||
# include <abstractions/dbus-accessibility>
|
||||
#
|
||||
# # Add if audio support for message box is
|
||||
# # considered as required.
|
||||
# #include if exists <abstractions/gstreamer>
|
||||
# include if exists <abstractions/gstreamer>
|
||||
#
|
||||
# # < add additional allowed applications here >
|
||||
# }
|
||||
# ```
|
||||
|
||||
#include <abstractions/audio> # for alert messages
|
||||
#include <abstractions/base>
|
||||
#include <abstractions/dbus-accessibility-strict>
|
||||
#include <abstractions/dbus-network-manager-strict>
|
||||
#include <abstractions/dbus-session-strict>
|
||||
#include <abstractions/dbus-strict>
|
||||
#include <abstractions/kde-icon-cache-write>
|
||||
#include <abstractions/kde>
|
||||
#include <abstractions/nameservice> # for IceProcessMessages () from libICE.so (called by libQtCore.so)
|
||||
#include <abstractions/openssl>
|
||||
#include <abstractions/qt5>
|
||||
#include <abstractions/recent-documents-write>
|
||||
#include <abstractions/X>
|
||||
include <abstractions/audio> # for alert messages
|
||||
include <abstractions/base>
|
||||
include <abstractions/dbus-accessibility-strict>
|
||||
include <abstractions/dbus-network-manager-strict>
|
||||
include <abstractions/dbus-session-strict>
|
||||
include <abstractions/dbus-strict>
|
||||
include <abstractions/kde-icon-cache-write>
|
||||
include <abstractions/kde>
|
||||
include <abstractions/nameservice> # for IceProcessMessages () from libICE.so (called by libQtCore.so)
|
||||
include <abstractions/openssl>
|
||||
include <abstractions/qt5>
|
||||
include <abstractions/recent-documents-write>
|
||||
include <abstractions/X>
|
||||
|
||||
# Main executables
|
||||
|
||||
@@ -96,9 +98,9 @@
|
||||
# User files
|
||||
|
||||
owner /tmp/xauth-[0-9]*-_[0-9] r, # for libQt5XcbQpa.so
|
||||
owner /{,var/}run/user/[0-9]*/#[0-9]* rw, # for /run/user/1000/#13
|
||||
owner /{,var/}run/user/[0-9]*/kioclient*slave-socket lrw -> /{,var/}/run/user/[0-9]/#[0-9]*, # for KIO::Slave::holdSlave(QString const&, QUrl const&) () from libKF5KIOCore.so (not 100% sure)
|
||||
owner @{run}/user/[0-9]*/#[0-9]* rw, # for /run/user/1000/#13
|
||||
owner @{run}/user/[0-9]*/kioclient*slave-socket lrw -> @{run}/user/[0-9]/#[0-9]*, # for KIO::Slave::holdSlave(QString const&, QUrl const&) () from libKF5KIOCore.so (not 100% sure)
|
||||
owner @{HOME}/.cache/kio_http/ rw,
|
||||
|
||||
# Include additions to the abstraction
|
||||
#include if exists <abstractions/kde-open5.d>
|
||||
include if exists <abstractions/kde-open5.d>
|
||||
|
||||
@@ -9,6 +9,8 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# files required by kerberos client programs
|
||||
/usr/lib{,32,64}/krb5/plugins/libkrb5/ r,
|
||||
/usr/lib{,32,64}/krb5/plugins/libkrb5/* mr,
|
||||
@@ -32,3 +34,6 @@
|
||||
|
||||
# credential caches
|
||||
/tmp/krb5cc* r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/kerberosclient.d>
|
||||
|
||||
@@ -8,6 +8,8 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# files required by LDAP clients (e.g. nss_ldap/pam_ldap)
|
||||
/etc/ldap.conf r,
|
||||
/etc/ldap.secret r,
|
||||
@@ -19,6 +21,9 @@
|
||||
/usr/lib{,32,64}/sasl2/* r,
|
||||
|
||||
# local LDAP name service daemon
|
||||
/{,var/}run/nslcd/socket rw,
|
||||
@{run}/nslcd/socket rw,
|
||||
|
||||
#include <abstractions/ssl_certs>
|
||||
include <abstractions/ssl_certs>
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/ldapclient.d>
|
||||
|
||||
@@ -9,7 +9,9 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
#include <abstractions/dbus-strict>
|
||||
abi <abi/3.0>,
|
||||
|
||||
include <abstractions/dbus-strict>
|
||||
|
||||
# libpam-systemd notifies systemd-logind about session logins/logouts
|
||||
dbus send
|
||||
@@ -17,3 +19,6 @@
|
||||
path=/org/freedesktop/login1
|
||||
interface=org.freedesktop.login1.Manager
|
||||
member={CreateSession,ReleaseSession},
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/libpam-systemd.d>
|
||||
|
||||
@@ -9,5 +9,10 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
/tmp/.lwidentity/pipe rw,
|
||||
/var/lib/likewise-open/lwidentity_privileged/pipe rw,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/likewise.d>
|
||||
|
||||
@@ -8,7 +8,12 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# mdnsd
|
||||
/etc/mdns.allow r,
|
||||
/etc/nss_mdns.conf r,
|
||||
/{,var/}run/mdnsd w,
|
||||
@{run}/mdnsd w,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/mdns.d>
|
||||
|
||||
@@ -1,6 +1,8 @@
|
||||
# vim:syntax=apparmor
|
||||
# Rules for Mesa implementation of the OpenGL API
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# System files
|
||||
/dev/dri/ r, # libGLX_mesa.so calls drmGetDevice2()
|
||||
|
||||
@@ -8,10 +10,22 @@
|
||||
# (src/intel/perf/gen_perf.c, load_oa_metrics())
|
||||
@{PROC}/sys/dev/i915/perf_stream_paranoid r,
|
||||
|
||||
@{sys}/devices/pci[0-9]*/**/{revision,config} r,
|
||||
|
||||
# User files
|
||||
owner @{HOME}/.cache/ w, # if user clears all caches
|
||||
owner @{HOME}/.cache/mesa_shader_cache/ w,
|
||||
owner @{HOME}/.cache/mesa_shader_cache/ rw,
|
||||
owner @{HOME}/.cache/mesa_shader_cache/index rw,
|
||||
owner @{HOME}/.cache/mesa_shader_cache/??/ w,
|
||||
owner @{HOME}/.cache/mesa_shader_cache/??/* rwk,
|
||||
owner @{HOME}/.cache/mesa_shader_cache/[a-f0-9][a-f0-9]/ rw,
|
||||
owner @{HOME}/.cache/mesa_shader_cache/[a-f0-9][a-f0-9]/[0-9a-f]* rw,
|
||||
owner @{HOME}/.cache/mesa_shader_cache/[a-f0-9][a-f0-9]/[0-9a-f]*.tmp rwk,
|
||||
|
||||
# Fallback location when @{HOME}/.cache is not available
|
||||
owner /tmp/Temp-[a-f0-9]*/mesa_shader_cache/ rw,
|
||||
owner /tmp/Temp-[a-f0-9]*/mesa_shader_cache/index rw,
|
||||
owner /tmp/Temp-[a-f0-9]*/mesa_shader_cache/[a-f0-9][a-f0-9]/ rw,
|
||||
owner /tmp/Temp-[a-f0-9]*/mesa_shader_cache/[a-f0-9][a-f0-9]/[0-9a-f]* rw,
|
||||
owner /tmp/Temp-[a-f0-9]*/mesa_shader_cache/[a-f0-9][a-f0-9]/[0-9a-f]*.tmp rwk,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/mesa.d>
|
||||
|
||||
@@ -9,9 +9,14 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# mir libraries sometimes do not have a lib prefix
|
||||
# see LP: #1422521
|
||||
/usr/lib/@{multiarch}/mir/*.so* mr,
|
||||
/usr/lib/@{multiarch}/mir/**/*.so* mr,
|
||||
|
||||
# unprivileged mir socket for clients
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/mir.d>
|
||||
|
||||
@@ -9,4 +9,9 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
unix (connect, receive, send) type=stream peer=(addr="@tmp/.mozc.*"),
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/mozc.d>
|
||||
|
||||
@@ -9,7 +9,12 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
/var/lib/mysql{,d}/mysql{,d}.sock rw,
|
||||
/{var/,}run/mysql{,d}/mysql{,d}.sock rw,
|
||||
@{run}/mysql{,d}/mysql{,d}.sock rw,
|
||||
/usr/share/{mysql,mysql-community-server,mariadb}/charsets/ r,
|
||||
/usr/share/{mysql,mysql-community-server,mariadb}/charsets/*.xml r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/mysql.d>
|
||||
|
||||
@@ -9,31 +9,28 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# Many programs wish to perform nameservice-like operations, such as
|
||||
# looking up users by name or id, groups by name or id, hosts by name
|
||||
# or IP, etc. These operations may be performed through files, dns,
|
||||
# NIS, NIS+, LDAP, hesiod, wins, etc. Allow them all here.
|
||||
/etc/group r,
|
||||
/etc/host.conf r,
|
||||
/etc/hosts r,
|
||||
/etc/nsswitch.conf r,
|
||||
/etc/gai.conf r,
|
||||
/etc/passwd r,
|
||||
/etc/protocols r,
|
||||
@{etc_ro}/group r,
|
||||
@{etc_ro}/host.conf r,
|
||||
@{etc_ro}/hosts r,
|
||||
@{etc_ro}/nsswitch.conf r,
|
||||
@{etc_ro}/gai.conf r,
|
||||
@{etc_ro}/passwd r,
|
||||
@{etc_ro}/protocols r,
|
||||
|
||||
# libtirpc (used for NIS/YP login) needs this
|
||||
/etc/netconfig r,
|
||||
@{etc_ro}/netconfig r,
|
||||
|
||||
# When using libnss-extrausers, the passwd and group files are merged from
|
||||
# an alternate path
|
||||
/var/lib/extrausers/group r,
|
||||
/var/lib/extrausers/passwd r,
|
||||
|
||||
# NSS records from systemd-userdbd.service
|
||||
@{run}/systemd/userdb/ r,
|
||||
@{run}/systemd/userdb/io.systemd.{NameServiceSwitch,Multiplexer,DynamicUser,Home} r,
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
|
||||
# When using sssd, the passwd and group files are stored in an alternate path
|
||||
# and the nss plugin also needs to talk to a pipe
|
||||
/var/lib/sss/mc/group r,
|
||||
@@ -41,56 +38,69 @@
|
||||
/var/lib/sss/mc/passwd r,
|
||||
/var/lib/sss/pipes/nss rw,
|
||||
|
||||
/etc/resolv.conf r,
|
||||
@{etc_ro}/resolv.conf r,
|
||||
# On systems where /etc/resolv.conf is managed programmatically, it is
|
||||
# a symlink to /{,var/}run/(whatever program is managing it)/resolv.conf.
|
||||
/{,var/}run/{resolvconf,NetworkManager,systemd/resolve,connman,netconfig}/resolv.conf r,
|
||||
/etc/resolvconf/run/resolv.conf r,
|
||||
/{,var/}run/systemd/resolve/stub-resolv.conf r,
|
||||
# a symlink to @{run}/(whatever program is managing it)/resolv.conf.
|
||||
@{run}/{resolvconf,NetworkManager,systemd/resolve,connman,netconfig}/resolv.conf r,
|
||||
@{etc_ro}/resolvconf/run/resolv.conf r,
|
||||
@{run}/systemd/resolve/stub-resolv.conf r,
|
||||
/mnt/wsl/resolv.conf r,
|
||||
|
||||
/etc/samba/lmhosts r,
|
||||
/etc/services r,
|
||||
@{etc_ro}/samba/lmhosts r,
|
||||
@{etc_ro}/services r,
|
||||
# db backend
|
||||
/var/lib/misc/*.db r,
|
||||
# The Name Service Cache Daemon can cache lookups, sometimes leading
|
||||
# to vast speed increases when working with network-based lookups.
|
||||
/{,var/}run/.nscd_socket rw,
|
||||
/{,var/}run/nscd/socket rw,
|
||||
@{run}/.nscd_socket rw,
|
||||
@{run}/nscd/socket rw,
|
||||
/{var/db,var/cache,var/lib,var/run,run}/nscd/{passwd,group,services,hosts} r,
|
||||
# nscd renames and unlinks files in it's operation that clients will
|
||||
# have open
|
||||
/{,var/}run/nscd/db* rmix,
|
||||
@{run}/nscd/db* rmix,
|
||||
|
||||
# The nss libraries are sometimes used in addition to PAM; make sure
|
||||
# they are available
|
||||
/{usr/,}lib{,32,64}/libnss_*.so* mr,
|
||||
/{usr/,}lib/@{multiarch}/libnss_*.so* mr,
|
||||
/etc/default/nss r,
|
||||
@{etc_ro}/default/nss r,
|
||||
|
||||
# avahi-daemon is used for mdns4 resolution
|
||||
/{,var/}run/avahi-daemon/socket rw,
|
||||
@{run}/avahi-daemon/socket rw,
|
||||
|
||||
# libnl-3-200 via libnss-gw-name
|
||||
@{PROC}/@{pid}/net/psched r,
|
||||
/etc/libnl-*/classid r,
|
||||
@{etc_ro}/libnl-*/classid r,
|
||||
|
||||
# nis
|
||||
#include <abstractions/nis>
|
||||
include <abstractions/nis>
|
||||
|
||||
# ldap
|
||||
#include <abstractions/ldapclient>
|
||||
include <abstractions/ldapclient>
|
||||
|
||||
# winbind
|
||||
#include <abstractions/winbind>
|
||||
include <abstractions/winbind>
|
||||
|
||||
# likewise
|
||||
#include <abstractions/likewise>
|
||||
include <abstractions/likewise>
|
||||
|
||||
# mdnsd
|
||||
#include <abstractions/mdns>
|
||||
include <abstractions/mdns>
|
||||
|
||||
# kerberos
|
||||
#include <abstractions/kerberosclient>
|
||||
include <abstractions/kerberosclient>
|
||||
|
||||
#libnss-systemd
|
||||
include <abstractions/nss-systemd>
|
||||
|
||||
# Also allow lookups for systemd-exec's DynamicUsers via D-Bus
|
||||
# https://www.freedesktop.org/software/systemd/man/systemd.exec.html
|
||||
dbus send
|
||||
bus=system
|
||||
path="/org/freedesktop/systemd1"
|
||||
interface="org.freedesktop.systemd1.Manager"
|
||||
member="{GetDynamicUsers,LookupDynamicUserByName,LookupDynamicUserByUID}"
|
||||
peer=(name="org.freedesktop.systemd1"),
|
||||
|
||||
# TCP/UDP network access
|
||||
network inet stream,
|
||||
@@ -104,3 +114,6 @@
|
||||
|
||||
# interface details
|
||||
@{PROC}/@{pid}/net/route r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/nameservice.d>
|
||||
|
||||
@@ -8,8 +8,13 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# NIS rules
|
||||
/var/yp/binding/* r,
|
||||
# portmapper may ask root processes to do nis/ldap at low ports
|
||||
capability net_bind_service,
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/nis.d>
|
||||
|
||||
@@ -0,0 +1,31 @@
|
||||
# ------------------------------------------------------------------
|
||||
#
|
||||
# Copyright (C) 2002-2009 Novell/SUSE
|
||||
# Copyright (C) 2009-2011 Canonical Ltd.
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or
|
||||
# modify it under the terms of version 2 of the GNU General Public
|
||||
# License published by the Free Software Foundation.
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# libnss-systemd
|
||||
#
|
||||
# https://systemd.io/USER_GROUP_API/
|
||||
# https://systemd.io/USER_RECORD/
|
||||
# https://www.freedesktop.org/software/systemd/man/nss-systemd.html
|
||||
#
|
||||
# Allow User/Group lookups via common VarLink socket APIs. Applications need
|
||||
# to either consult all of them or the io.systemd.Multiplexer frontend.
|
||||
@{run}/systemd/userdb/ r,
|
||||
@{run}/systemd/userdb/io.systemd.Multiplexer rw,
|
||||
@{run}/systemd/userdb/io.systemd.DynamicUser rw, # systemd-exec users
|
||||
@{run}/systemd/userdb/io.systemd.Home rw, # systemd-home dirs
|
||||
@{run}/systemd/userdb/io.systemd.NameServiceSwitch rw, # UNIX/glibc NSS
|
||||
@{run}/systemd/userdb/io.systemd.Machine rw, # systemd-machined
|
||||
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
|
||||
include if exists <abstractions/nss-systemd.d>
|
||||
@@ -1,6 +1,8 @@
|
||||
# vim:syntax=apparmor
|
||||
# nvidia access requirements
|
||||
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# configuration queries
|
||||
capability ipc_lock,
|
||||
|
||||
@@ -24,5 +26,9 @@
|
||||
owner @{HOME}/.nv/ w,
|
||||
owner @{HOME}/.nv/GLCache/ rw,
|
||||
owner @{HOME}/.nv/GLCache/** rwk,
|
||||
owner @{PROC}/@{pid}/comm r, # somehwere in libnvidia-glcore.so
|
||||
|
||||
unix (send, receive) type=dgram peer=(addr="@nvidia[0-9a-f]*"),
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/nvidia.d>
|
||||
|
||||
@@ -1,9 +1,15 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# OpenCL access requirements
|
||||
|
||||
# TODO: use conditionals to select allowed implementations
|
||||
#include <abstractions/opencl-intel>
|
||||
#include <abstractions/opencl-mesa>
|
||||
#include <abstractions/opencl-nvidia>
|
||||
#include <abstractions/opencl-pocl>
|
||||
include <abstractions/opencl-intel>
|
||||
include <abstractions/opencl-mesa>
|
||||
include <abstractions/opencl-nvidia>
|
||||
include <abstractions/opencl-pocl>
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/opencl.d>
|
||||
|
||||
@@ -1,4 +1,7 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# implementation-independent OpenCL access requirements
|
||||
|
||||
# System files
|
||||
@@ -8,3 +11,6 @@
|
||||
@{sys}/devices/system/node/ r, # for clGetPlatformIDs() from libOpenCL.so
|
||||
@{sys}/devices/system/node/node[0-9]*/meminfo r, # for clGetPlatformIDs() from libOpenCL.so
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/opencl-common.d>
|
||||
|
||||
@@ -1,13 +1,16 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# OpenCL access requirements for Intel implementation
|
||||
|
||||
#include <abstractions/opencl-common>
|
||||
include <abstractions/opencl-common>
|
||||
|
||||
# for libcl.so (libOpenCL.so -> beignet/libcl.so calls XOpenDisplay())
|
||||
#include <abstractions/X>
|
||||
include <abstractions/X>
|
||||
|
||||
# for libOpenCL.so -> beignet/libcl.so -> libpciaccess.so
|
||||
#include <abstractions/dri-enumerate>
|
||||
include <abstractions/dri-enumerate>
|
||||
|
||||
# System files
|
||||
|
||||
@@ -15,3 +18,6 @@
|
||||
@{sys}/devices/pci[0-9]*/**/{class,config,resource,revision} r, # libcl.so -> libdrm_intel.so -> libpciaccess.so (move to dri-enumerate ?)
|
||||
/usr/lib/@{multiarch}/beignet/** r,
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/opencl-intel.d>
|
||||
|
||||
@@ -1,7 +1,10 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# OpenCL access requirements for Mesa implementation
|
||||
|
||||
#include <abstractions/opencl-common>
|
||||
include <abstractions/opencl-common>
|
||||
|
||||
# Additional libraries
|
||||
|
||||
@@ -18,3 +21,6 @@
|
||||
|
||||
owner @{HOME}/.cache/mesa_shader_cache/{,**} rw, # libMesaOpenCL.so -> pipe_nouveau.so
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/opencl-mesa.d>
|
||||
|
||||
@@ -1,8 +1,11 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# OpenCL access requirements for NVIDIA implementation
|
||||
|
||||
#include <abstractions/nvidia>
|
||||
#include <abstractions/opencl-common>
|
||||
include <abstractions/nvidia>
|
||||
include <abstractions/opencl-common>
|
||||
|
||||
# Executables
|
||||
|
||||
@@ -28,3 +31,6 @@
|
||||
owner @{HOME}/.nv/ComputeCache/** rw,
|
||||
owner @{HOME}/.nv/ComputeCache/index rwk,
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/opencl-nvidia.d>
|
||||
|
||||
@@ -1,7 +1,9 @@
|
||||
# vim:syntax=apparmor
|
||||
# OpenCL access requirements for POCL implementation
|
||||
|
||||
#include <abstractions/opencl-common>
|
||||
abi <abi/3.0>,
|
||||
|
||||
include <abstractions/opencl-common>
|
||||
|
||||
# Executables
|
||||
|
||||
@@ -28,7 +30,7 @@
|
||||
@{sys}/fs/cgroup/cpuset/cpuset.{cpus,mems} r, # libpocl.so -> libhwloc.so
|
||||
@{sys}/kernel/mm/hugepages{/,/**} r, # libpocl.so -> libhwloc.so
|
||||
/usr/share/pocl/** r,
|
||||
/{,var/}run/udev/data/*:* r, # libpocl.so -> hwloc_linux_block_class_fillinfos() from libhwloc.so
|
||||
@{run}/udev/data/*:* r, # libpocl.so -> hwloc_linux_block_class_fillinfos() from libhwloc.so
|
||||
|
||||
# User files
|
||||
|
||||
@@ -41,7 +43,7 @@
|
||||
# Child profiles
|
||||
|
||||
profile opencl_pocl_ld {
|
||||
#include <abstractions/base>
|
||||
include <abstractions/base>
|
||||
|
||||
# Main executables
|
||||
|
||||
@@ -54,7 +56,7 @@
|
||||
}
|
||||
|
||||
profile opencl_pocl_clang {
|
||||
#include <abstractions/base>
|
||||
include <abstractions/base>
|
||||
|
||||
# Main executables
|
||||
|
||||
@@ -74,3 +76,6 @@
|
||||
owner @{HOME}/.cache/pocl/kcache/*/*/*/*/*.so{,.o} rw,
|
||||
}
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/opencl-pocl.d>
|
||||
|
||||
@@ -8,7 +8,14 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
/etc/ssl/openssl.cnf r,
|
||||
/etc/ssl/{engdef,engines}.d/ r,
|
||||
/etc/ssl/{engdef,engines}.d/*.cnf r,
|
||||
/usr/share/ssl/openssl.cnf r,
|
||||
@{PROC}/sys/crypto/fips_enabled r,
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/openssl.d>
|
||||
|
||||
@@ -1,5 +1,10 @@
|
||||
# vim:syntax=apparmor
|
||||
# orbit2 permissions
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# system library
|
||||
/usr/lib/orbit-2.0/*.so mr,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/orbit2.d>
|
||||
|
||||
@@ -8,6 +8,8 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
/etc/pkcs11/ r,
|
||||
/etc/pkcs11/pkcs11.conf r,
|
||||
/etc/pkcs11/modules/ r,
|
||||
@@ -20,8 +22,11 @@
|
||||
/usr/share/p11-kit/modules/* r,
|
||||
|
||||
# gnome-keyring pkcs11 module
|
||||
owner /{,var/}run/user/[0-9]*/keyring*/pkcs11 rw,
|
||||
owner @{run}/user/[0-9]*/keyring*/pkcs11 rw,
|
||||
|
||||
# p11-kit also supports reading user configuration from ~/.pkcs11 depending
|
||||
# on how /etc/pkcs11/pkcs11.conf is configured. This should generally not be
|
||||
# included in this abstraction.
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/p11-kit.d>
|
||||
|
||||
@@ -9,6 +9,8 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# a few files typically required for perl scripts
|
||||
/usr/bin/perl rmix,
|
||||
/usr/bin/perl[0-9].[0-9].[0-9] rmix,
|
||||
@@ -21,3 +23,6 @@
|
||||
/usr/share/perl/** r,
|
||||
/usr/share/perl5/** r,
|
||||
/etc/perl/** r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/perl.d>
|
||||
|
||||
@@ -10,30 +10,34 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# shared snippets for config files
|
||||
/etc/php{,5,7}/**/ r,
|
||||
/etc/php{,5,7}/**.ini r,
|
||||
/etc/php{,5,7,8}/** r,
|
||||
|
||||
# Xlibs
|
||||
/usr/X11R6/lib{,32,64}/lib*.so* mr,
|
||||
# php extensions
|
||||
/usr/lib{64,}/php{,5,7}/*/*.so mr,
|
||||
/usr/lib{64,}/php{,5,7,8}/*/*.so mr,
|
||||
|
||||
# ICU (unicode support) data tables
|
||||
/usr/share/icu/*/*.dat r,
|
||||
|
||||
# php session mmap socket
|
||||
/var/lib/php{,5,7}/session_mm_* rwlk,
|
||||
/var/lib/php{,5,7,8}/session_mm_* rwlk,
|
||||
# file based session handler
|
||||
/var/lib/php{,5,7}/sess_* rwlk,
|
||||
/var/lib/php{,5,7}/sessions/* rwlk,
|
||||
/var/lib/php{,5,7,8}/sess_* rwlk,
|
||||
/var/lib/php{,5,7,8}/sessions/* rwlk,
|
||||
|
||||
# php libraries
|
||||
/usr/share/php{,5,7}/ r,
|
||||
/usr/share/php{,5,7}/** mr,
|
||||
/usr/share/php{,5,7,8}/ r,
|
||||
/usr/share/php{,5,7,8}/** mr,
|
||||
|
||||
# MySQL extension
|
||||
/usr/share/mysql/** r,
|
||||
|
||||
# Zend opcache
|
||||
/tmp/.ZendSem.* rwlk,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/php.d>
|
||||
|
||||
@@ -0,0 +1,22 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
# This file contains basic permissions for php-fpm workers
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# load common libraries and their support files
|
||||
include <abstractions/base>
|
||||
# common php files and support files that php needs
|
||||
include <abstractions/php>
|
||||
|
||||
signal (receive) peer=php-fpm,
|
||||
|
||||
# This is some php opcaching file
|
||||
/tmp/.ZendSem.* rwk,
|
||||
|
||||
# I think this is adaptive memory management
|
||||
/sys/devices/system/node/* r,
|
||||
/sys/devices/system/node/*/meminfo r,
|
||||
/sys/devices/system/node/ r,
|
||||
|
||||
include if exists <abstractions/php-worker.d>
|
||||
@@ -1,3 +1,8 @@
|
||||
#backwards compatibility include, actual abstraction moved from php5 to php
|
||||
|
||||
#include <abstractions/php>
|
||||
abi <abi/3.0>,
|
||||
|
||||
include <abstractions/php>
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/php5.d>
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
#
|
||||
# Copyright (C) 2002-2005 Novell/SUSE
|
||||
# Copyright (C) 2015-2018 Canonical, Ltd.
|
||||
# Copyright (C) 2020 Christian Boltz
|
||||
# Copyright (C) 2020-2021 Christian Boltz
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or
|
||||
# modify it under the terms of version 2 of the GNU General Public
|
||||
@@ -11,21 +11,22 @@
|
||||
# ------------------------------------------------------------------
|
||||
# used with postfix/*
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
|
||||
capability setuid,
|
||||
capability setgid,
|
||||
capability sys_chroot,
|
||||
|
||||
# postfix's master can send us signals
|
||||
signal receive peer=/usr/lib/postfix/master,
|
||||
signal receive peer=postfix-master,
|
||||
|
||||
unix (send, receive) peer=(label=/usr/lib/postfix/master),
|
||||
unix (send, receive) peer=(label=postfix-master),
|
||||
|
||||
/etc/mailname r,
|
||||
/etc/postfix/*.cf r,
|
||||
/etc/postfix/*.db rk,
|
||||
/etc/postfix/*.lmdb rk,
|
||||
@{PROC}/net/if_inet6 r,
|
||||
/usr/lib/postfix/*.so mr,
|
||||
/usr/lib{,32,64}/sasl2/* mr,
|
||||
@@ -37,3 +38,8 @@
|
||||
/var/spool/postfix/etc/* r,
|
||||
/var/spool/postfix/lib/lib*.so* mr,
|
||||
/var/spool/postfix/lib/@{multiarch}/lib*.so* mr,
|
||||
|
||||
/etc/postfix/dynamicmaps.cf.d/ r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/postfix-common.d>
|
||||
|
||||
@@ -2,6 +2,8 @@
|
||||
# privacy-violations contains rules for common files that you want to
|
||||
# explicitly deny access
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# privacy violations (don't audit files under $HOME otherwise get a
|
||||
# lot of false positives when reading contents of directories)
|
||||
deny @{HOME}/.*history mrwkl,
|
||||
@@ -45,3 +47,6 @@
|
||||
|
||||
deny @{HOME}/.zshenv mrk,
|
||||
audit deny @{HOME}/.zshenv wl,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/private-files.d>
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
# privacy-violations-strict contains additional rules for sensitive
|
||||
# files that you want to explicitly deny access
|
||||
|
||||
#include <abstractions/private-files>
|
||||
abi <abi/3.0>,
|
||||
|
||||
include <abstractions/private-files>
|
||||
|
||||
# potentially extremely sensitive files
|
||||
audit deny @{HOME}/.aws/{,**} mrwkl,
|
||||
@@ -12,7 +14,7 @@
|
||||
audit deny @{HOME}/.gnome2/ w,
|
||||
audit deny @{HOME}/.gnome2/keyrings/{,**} mrwkl,
|
||||
# don't allow access to any gnome-keyring modules
|
||||
audit deny /{,var/}run/user/[0-9]*/keyring** mrwkl,
|
||||
audit deny @{run}/user/[0-9]*/keyring** mrwkl,
|
||||
audit deny @{HOME}/.mozilla/{,**} mrwkl,
|
||||
audit deny @{HOME}/.config/ w,
|
||||
audit deny @{HOME}/.config/chromium/{,**} mrwkl,
|
||||
@@ -22,4 +24,7 @@
|
||||
audit deny @{HOME}/.kde{,4}/{,share/,share/apps/} w,
|
||||
audit deny @{HOME}/.kde{,4}/share/apps/kmail{,2}/{,**} mrwkl,
|
||||
audit deny @{HOME}/.kde{,4}/share/apps/kwallet/{,**} mrwkl,
|
||||
audit deny @{HOME}/.local/share/kwalletd/{,**} mrwkl,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/private-files-strict.d>
|
||||
|
||||
@@ -10,18 +10,19 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
/usr/lib{,32,64}/python{2.[4-7],3.[0-9]}/**.{pyc,so} mr,
|
||||
/usr/lib{,32,64}/python{2.[4-7],3.[0-9]}/**.{egg,py,pth} r,
|
||||
/usr/lib{,32,64}/python{2.[4-7],3.[0-9]}/{site,dist}-packages/ r,
|
||||
/usr/lib{,32,64}/python3.[0-9]/lib-dynload/*.so mr,
|
||||
abi <abi/3.0>,
|
||||
|
||||
/usr/local/lib{,32,64}/python{2.[4-7],3,3.[0-9]}/**.{pyc,so} mr,
|
||||
/usr/local/lib{,32,64}/python{2.[4-7],3,3.[0-9]}/**.{egg,py,pth} r,
|
||||
/usr/local/lib{,32,64}/python{2.[4-7],3,3.[0-9]}/{site,dist}-packages/ r,
|
||||
/usr/local/lib{,32,64}/python3.[0-9]/lib-dynload/*.so mr,
|
||||
/usr/{local/,}lib{,32,64}/python{2.[4-7],3,3.[0-9],3.1[0-9]}/**.{pyc,so,so.*[0-9]} mr,
|
||||
/usr/{local/,}lib{,32,64}/python{2.[4-7],3,3.[0-9],3.1[0-9]}/**.{egg,py,pth} r,
|
||||
/usr/{local/,}lib{,32,64}/python{2.[4-7],3,3.[0-9],3.1[0-9]}/{site,dist}-packages/ r,
|
||||
/usr/{local/,}lib{,32,64}/python{2.[4-7],3,3.[0-9],3.1[0-9]}/{site,dist}-packages/**/ r,
|
||||
/usr/{local/,}lib{,32,64}/python{2.[4-7],3,3.[0-9],3.1[0-9]}/{site,dist}-packages/*.dist-info/{METADATA,namespace_packages.txt} r,
|
||||
/usr/{local/,}lib{,32,64}/python{2.[4-7],3,3.[0-9],3.1[0-9]}/{site,dist}-packages/*.VERSION r,
|
||||
/usr/{local/,}lib{,32,64}/python{2.[4-7],3,3.[0-9],3.1[0-9]}/{site,dist}-packages/*.egg-info/PKG-INFO r,
|
||||
/usr/{local/,}lib{,32,64}/python3.{1,}[0-9]/lib-dynload/*.so mr,
|
||||
|
||||
# Site-wide configuration
|
||||
/etc/python{2.[4-7],3.[0-9]}/** r,
|
||||
/etc/python{2.[4-7],3.[0-9],3.1[0-9]}/** r,
|
||||
|
||||
# shared python paths
|
||||
/usr/share/{pyshared,pycentral,python-support}/** r,
|
||||
@@ -34,4 +35,7 @@
|
||||
/usr/lib/wx/python/*.pth r,
|
||||
|
||||
# python build configuration and headers
|
||||
/usr/include/python{2.[4-7],3.[0-9]}*/pyconfig.h r,
|
||||
/usr/include/python{2.[4-7],3.[0-9],3.1[0-9]}*/pyconfig.h r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/python.d>
|
||||
|
||||
@@ -1,6 +1,8 @@
|
||||
# vim:syntax=apparmor
|
||||
# Common rules for Qt5-based applications
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# Additional libraries
|
||||
|
||||
/usr/lib{,64,/@{multiarch}}/qt5/plugins/**.so mr,
|
||||
@@ -20,3 +22,6 @@
|
||||
owner @{HOME}/.config/QtProject.conf r, # common settings for QFileDialog, etc (application might need write access)
|
||||
owner @{HOME}/.cache/qt_compose_cache_{little,big}_endian_* r, # for "platforminputcontexts" plugins
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/qt5.d>
|
||||
|
||||
@@ -1,8 +1,13 @@
|
||||
# vim:syntax=apparmor
|
||||
# Allow writing cache for Qt5 "platforminputcontexts" plugins
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# User files
|
||||
|
||||
owner @{HOME}/.cache/qt_compose_cache_{little,big}_endian_* rwl -> @{HOME}/.cache/#[0-9]*[0-9],
|
||||
owner @{HOME}/.cache/#[0-9]*[0-9] rw, # QSaveFile (anonymous shared memory)
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/qt5-compose-cache-write.d>
|
||||
|
||||
@@ -1,6 +1,8 @@
|
||||
# vim:syntax=apparmor
|
||||
# Allow writing shared settings for Qt-based applications
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# User files
|
||||
|
||||
owner @{HOME}/.config/#[0-9]*[0-9] rw,
|
||||
@@ -9,3 +11,6 @@
|
||||
owner @{HOME}/.config/QtProject.conf.?????? rwl -> @{HOME}/.config/#[0-9]*[0-9],
|
||||
owner @{HOME}/.config/QtProject.conf.lock rwk,
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/qt5-settings-write.d>
|
||||
|
||||
@@ -1,6 +1,8 @@
|
||||
# vim:syntax=apparmor
|
||||
# Allow updating recent documents
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# User files
|
||||
|
||||
owner @{HOME}/.local/share/RecentDocuments/ rw,
|
||||
@@ -8,3 +10,6 @@
|
||||
owner @{HOME}/.local/share/RecentDocuments/*.desktop rwl -> @{HOME}/.local/share/RecentDocuments/#[0-9]*,
|
||||
owner @{HOME}/.local/share/RecentDocuments/*.lock rwk,
|
||||
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/recent-documents-write.d>
|
||||
|
||||
@@ -9,6 +9,8 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
/usr/lib{,32,64}/ruby/1.[89]{.[0-9],}/ r,
|
||||
/usr/lib{,32,64}/ruby/1.[89]{.[0-9],}/**.rb r,
|
||||
/usr/lib{,32,64}/ruby/1.[89]{.[0-9],}/*-linux/**.so mr,
|
||||
@@ -19,3 +21,6 @@
|
||||
|
||||
/usr/lib{,32,64}/ruby/gems/1.[89]{.[0-9],}/ r,
|
||||
/usr/lib{,32,64}/ruby/gems/1.[89]{.[0-9],}/** r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/ruby.d>
|
||||
|
||||
@@ -9,8 +9,12 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
/etc/samba/* r,
|
||||
/usr/lib*/ldb/*.so mr,
|
||||
/usr/lib*/ldb2/*.so mr,
|
||||
/usr/lib*/ldb2/modules/ldb/*.so mr,
|
||||
/usr/lib*/samba/ldb/*.so mr,
|
||||
/usr/share/samba/*.dat r,
|
||||
/usr/share/samba/codepages/{lowcase,upcase,valid}.dat r,
|
||||
@@ -20,8 +24,17 @@
|
||||
/var/log/samba/cores/ rw,
|
||||
/var/log/samba/cores/** rw,
|
||||
/var/log/samba/* w,
|
||||
/{,var/}run/samba/ w,
|
||||
/{,var/}run/samba/*.tdb rw,
|
||||
@{run}/{,lock/}samba/ w,
|
||||
@{run}/{,lock/}samba/*.tdb rwk,
|
||||
@{run}/{,lock/}samba/msg.{lock,sock}/ rwk,
|
||||
@{run}/{,lock/}samba/msg.{lock,sock}/[0-9]* rwk,
|
||||
/var/cache/samba/msg.lock/ rwk,
|
||||
/var/cache/samba/msg.lock/[0-9]* rwk,
|
||||
|
||||
# required for clustering
|
||||
/var/lib/ctdb/** rwk,
|
||||
|
||||
deny capability net_admin, # noisy setsockopt() calls from systemd
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/samba.d>
|
||||
|
||||
@@ -0,0 +1,30 @@
|
||||
# ------------------------------------------------------------------
|
||||
#
|
||||
# Copyright (C) 2022 SUSE LLC
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or
|
||||
# modify it under the terms of version 2 of the GNU General Public
|
||||
# License published by the Free Software Foundation.
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
# vim:syntax=apparmor
|
||||
|
||||
# This file contains basic permissions for samba rpcd_xyz services
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
include <abstractions/base>
|
||||
include <abstractions/nameservice>
|
||||
include <abstractions/samba>
|
||||
|
||||
capability setgid,
|
||||
capability setuid,
|
||||
|
||||
signal receive set=term peer=smbd,
|
||||
|
||||
@{PROC}/sys/kernel/core_pattern r,
|
||||
owner @{PROC}/@{pid}/fd/ r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/samba-rpcd.d>
|
||||
|
||||
@@ -9,5 +9,10 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# libpam-smbpass/pam_smbpass.so permissions
|
||||
/var/lib/samba/*.[lt]db rwk,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/smbpass.d>
|
||||
|
||||
@@ -0,0 +1,42 @@
|
||||
profile snap_browsers {
|
||||
include if exists <abstractions/snap_browsers.d>
|
||||
include <abstractions/base>
|
||||
include <abstractions/dbus-session-strict>
|
||||
|
||||
/etc/passwd r,
|
||||
/etc/nsswitch.conf r,
|
||||
/etc/fstab r,
|
||||
|
||||
# noisy
|
||||
deny owner /run/user/[0-9]*/gdm/Xauthority r, # not needed on Ubuntu
|
||||
|
||||
/{,snap/core/[0-9]*/,snap/snapd/[0-9]*/}usr/bin/snap mrix, # re-exec
|
||||
/{,snap/core/[0-9]*/,snap/snapd/[0-9]*/}usr/lib/snapd/info r,
|
||||
/{,snap/core/[0-9]*/,snap/snapd/[0-9]*/}usr/lib/snapd/snapd r,
|
||||
/{,snap/core/[0-9]*/,snap/snapd/[0-9]*/}usr/lib/snapd/snap-seccomp rPix,
|
||||
/{,snap/core/[0-9]*/,snap/snapd/[0-9]*/}usr/lib/snapd/snap-confine Pix,
|
||||
/var/lib/snapd/system-key r,
|
||||
/run/snapd.socket rw,
|
||||
|
||||
@{PROC}/version r,
|
||||
@{PROC}/cmdline r,
|
||||
@{PROC}/sys/net/core/somaxconn r,
|
||||
@{PROC}/sys/kernel/seccomp/actions_avail r,
|
||||
@{PROC}/sys/kernel/random/uuid r,
|
||||
owner @{PROC}/@{pid}/cgroup r,
|
||||
owner @{PROC}/@{pid}/mountinfo r,
|
||||
owner @{HOME}/.snap/auth.json r, # if exists, required
|
||||
|
||||
dbus send bus="session" path="/org/freedesktop/systemd1" interface="org.freedesktop.systemd1.Manager" member="StartTransientUnit" peer=(name="org.freedesktop.systemd1"),
|
||||
dbus receive bus="session" path="/org/freedesktop/systemd1" interface="org.freedesktop.systemd1.Manager" member="JobRemoved",
|
||||
|
||||
/sys/kernel/security/apparmor/features/ r,
|
||||
|
||||
# allow launching official browser snaps.
|
||||
/snap/chromium/[0-9]*/meta/{snap.yaml,hooks/} r,
|
||||
/snap/firefox/[0-9]*/meta/{snap.yaml,hooks/} r,
|
||||
/snap/opera/[0-9]*/meta/{snap.yaml,hooks/} r,
|
||||
|
||||
/var/lib/snapd/sequence/{chromium,firefox,opera}.json r,
|
||||
# add other browsers here
|
||||
}
|
||||
@@ -9,20 +9,19 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
/etc/ssl/ r,
|
||||
/etc/ssl/certs/ r,
|
||||
/etc/ssl/certs/* r,
|
||||
/etc/pki/trust/ r,
|
||||
/etc/pki/trust/* r,
|
||||
/etc/pki/trust/anchors/ r,
|
||||
/etc/pki/trust/anchors/** r,
|
||||
/usr/share/ca-certificates/ r,
|
||||
/usr/share/ca-certificates/** r,
|
||||
abi <abi/3.0>,
|
||||
|
||||
/etc/ca-certificates/{,**} r,
|
||||
/etc/{,libre}ssl/ r,
|
||||
/etc/{,libre}ssl/cert.pem r,
|
||||
/etc/{,libre}ssl/certs/{,**} r,
|
||||
/{etc,usr/share}/pki/bl[ao]cklist/{,*} r,
|
||||
/{etc,usr/share}/pki/trust/{,*} r,
|
||||
/{etc,usr/share}/pki/trust/{bl[oa]cklist,anchors}/{,**} r,
|
||||
/usr/share/ca-certificates/{,**} r,
|
||||
/usr/share/ssl/certs/ca-bundle.crt r,
|
||||
/usr/local/share/ca-certificates/ r,
|
||||
/usr/local/share/ca-certificates/** r,
|
||||
/var/lib/ca-certificates/ r,
|
||||
/var/lib/ca-certificates/** r,
|
||||
/usr/local/share/ca-certificates/{,**} r,
|
||||
/var/lib/ca-certificates/{,**} r,
|
||||
|
||||
# acmetool
|
||||
/var/lib/acme/certs/*/chain r,
|
||||
@@ -42,3 +41,10 @@
|
||||
/etc/certbot/archive/*/cert*.pem r,
|
||||
/etc/certbot/archive/*/chain*.pem r,
|
||||
/etc/certbot/archive/*/fullchain*.pem r,
|
||||
|
||||
# crypto policies used by various libraries
|
||||
/etc/crypto-policies/*/*.txt r,
|
||||
/usr/share/crypto-policies/*/*.txt r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/ssl_certs.d>
|
||||
|
||||
@@ -9,6 +9,8 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# private ssl permissions
|
||||
|
||||
# Just include the whole /etc/ssl directory if we should have access to
|
||||
@@ -28,3 +30,6 @@
|
||||
/etc/letsencrypt/archive/*/privkey*.pem r,
|
||||
|
||||
/etc/certbot/archive/*/privkey*.pem r,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/ssl_keys.d>
|
||||
|
||||
@@ -8,6 +8,8 @@
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# This little snippet should abstract the read/write access to a repository.
|
||||
# it is intended to be included in profiles for svnserve/apache2 and maybe
|
||||
# some repository viewers like trac/viewvc
|
||||
@@ -50,3 +52,6 @@
|
||||
/tmp/apr* rwl,
|
||||
/var/tmp/apr* rwl,
|
||||
/tmp/report*.tmp rwl,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/svn-repositories.d>
|
||||
|
||||
@@ -2,9 +2,11 @@
|
||||
#
|
||||
# abstraction for allowing graphical bittorrent clients in Ubuntu
|
||||
#
|
||||
# Users of this abstraction need to #include the ubuntu-helpers abstraction
|
||||
# Users of this abstraction need to include the ubuntu-helpers abstraction
|
||||
# in the toplevel profile. Eg:
|
||||
# #include <abstractions/ubuntu-helpers>
|
||||
# include <abstractions/ubuntu-helpers>
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
/usr/bin/azureus Cxr -> sanitized_helper,
|
||||
/usr/bin/bitstormlite Cxr -> sanitized_helper,
|
||||
@@ -15,3 +17,6 @@
|
||||
/usr/bin/ktorrent Cxr -> sanitized_helper,
|
||||
/usr/bin/qbittorrent Cxr -> sanitized_helper,
|
||||
/usr/bin/transmission{,-gtk,-qt,-cli} Cxr -> sanitized_helper,
|
||||
|
||||
# Include additions to the abstraction
|
||||
include if exists <abstractions/ubuntu-bittorrent-clients.d>
|
||||
|
||||
@@ -2,25 +2,23 @@
|
||||
#
|
||||
# abstraction for allowing access to graphical browsers in Ubuntu
|
||||
#
|
||||
# Users of this abstraction need to #include the ubuntu-helpers abstraction
|
||||
# Users of this abstraction need to include the ubuntu-helpers abstraction
|
||||
# in the toplevel profile. Eg:
|
||||
# #include <abstractions/ubuntu-helpers>
|
||||
# include <abstractions/ubuntu-helpers>
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
/usr/bin/arora Cx -> sanitized_helper,
|
||||
/usr/bin/conkeror Cx -> sanitized_helper,
|
||||
/usr/bin/dillo Cx -> sanitized_helper,
|
||||
/usr/bin/Dooble Cx -> sanitized_helper,
|
||||
/usr/bin/epiphany Cx -> sanitized_helper,
|
||||
/usr/bin/epiphany-browser Cx -> sanitized_helper,
|
||||
/usr/bin/epiphany-webkit Cx -> sanitized_helper,
|
||||
/usr/lib/fennec-*/fennec Cx -> sanitized_helper,
|
||||
/usr/bin/galeon Cx -> sanitized_helper,
|
||||
/usr/bin/kazehakase Cx -> sanitized_helper,
|
||||
/usr/bin/konqueror Cx -> sanitized_helper,
|
||||
/usr/bin/midori Cx -> sanitized_helper,
|
||||
/usr/bin/netsurf Cx -> sanitized_helper,
|
||||
/usr/bin/prism Cx -> sanitized_helper,
|
||||
/usr/bin/rekonq Cx -> sanitized_helper,
|
||||
/usr/bin/seamonkey Cx -> sanitized_helper,
|
||||
/usr/bin/sensible-browser Pixr,
|
||||
|
||||
@@ -40,3 +38,4 @@
|
||||
/usr/lib/icecat-*/icecat Cx -> sanitized_helper,
|
||||
/usr/bin/opera Cx -> sanitized_helper,
|
||||
/opt/google/chrome{,-beta,-unstable}/google-chrome{,-beta,-unstable} Cx -> sanitized_helper,
|
||||
/opt/brave.com/brave{,-beta,-dev,-nightly}/brave-browser{,-beta,-dev,-nightly} Cx -> sanitized_helper,
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
# vim:syntax=apparmor
|
||||
# ------------------------------------------------------------------
|
||||
#
|
||||
# Copyright (C) 2020 Canonical Ltd.
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or
|
||||
# modify it under the terms of version 2 of the GNU General Public
|
||||
# License published by the Free Software Foundation.
|
||||
#
|
||||
# ------------------------------------------------------------------
|
||||
# Author: Jamie Strandboge <jamie@canonical.com>
|
||||
|
||||
# For site-specific adjustments, please see:
|
||||
# /etc/apparmor.d/local/chromium-browser
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
include <abstractions/ubuntu-browsers.d/plugins-common>
|
||||
include <abstractions/ubuntu-browsers.d/mailto>
|
||||
include <abstractions/ubuntu-browsers.d/multimedia>
|
||||
include <abstractions/ubuntu-browsers.d/productivity>
|
||||
include <abstractions/ubuntu-browsers.d/java>
|
||||
include <abstractions/ubuntu-browsers.d/kde>
|
||||
include <abstractions/ubuntu-browsers.d/text-editors>
|
||||
include <abstractions/ubuntu-browsers.d/ubuntu-integration>
|
||||
include <abstractions/ubuntu-browsers.d/user-files>
|
||||
@@ -1,5 +1,7 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# Java plugin
|
||||
owner @{HOME}/.java/deployment/deployment.properties k,
|
||||
/etc/java-*/ r,
|
||||
@@ -18,14 +20,14 @@
|
||||
# unfortunate workarounds of the proprietary Javas, so have a separate
|
||||
# profile.
|
||||
profile browser_openjdk {
|
||||
#include <abstractions/base>
|
||||
#include <abstractions/fonts>
|
||||
#include <abstractions/gnome>
|
||||
#include <abstractions/kde>
|
||||
#include <abstractions/nameservice>
|
||||
#include <abstractions/ssl_certs>
|
||||
#include <abstractions/user-tmp>
|
||||
#include <abstractions/private-files-strict>
|
||||
include <abstractions/base>
|
||||
include <abstractions/fonts>
|
||||
include <abstractions/gnome>
|
||||
include <abstractions/kde>
|
||||
include <abstractions/nameservice>
|
||||
include <abstractions/ssl_certs>
|
||||
include <abstractions/user-tmp>
|
||||
include <abstractions/private-files-strict>
|
||||
|
||||
network inet stream,
|
||||
network inet6 stream,
|
||||
@@ -64,14 +66,14 @@
|
||||
# Profile for commercial Javas. These need workarounds to work right (eg
|
||||
# Sun's forcing of an executable stack (LP: #535247)).
|
||||
profile browser_java {
|
||||
#include <abstractions/base>
|
||||
#include <abstractions/fonts>
|
||||
#include <abstractions/gnome>
|
||||
#include <abstractions/kde>
|
||||
#include <abstractions/nameservice>
|
||||
#include <abstractions/ssl_certs>
|
||||
#include <abstractions/user-tmp>
|
||||
#include <abstractions/private-files-strict>
|
||||
include <abstractions/base>
|
||||
include <abstractions/fonts>
|
||||
include <abstractions/gnome>
|
||||
include <abstractions/kde>
|
||||
include <abstractions/nameservice>
|
||||
include <abstractions/ssl_certs>
|
||||
include <abstractions/user-tmp>
|
||||
include <abstractions/private-files-strict>
|
||||
|
||||
network inet stream,
|
||||
network inet6 stream,
|
||||
|
||||
@@ -1,7 +1,9 @@
|
||||
# vim:syntax=apparmor
|
||||
# Users of this abstraction need to #include the ubuntu-helpers abstraction
|
||||
# Users of this abstraction need to include the ubuntu-helpers abstraction
|
||||
# in the toplevel profile. Eg:
|
||||
# #include <abstractions/ubuntu-helpers>
|
||||
# include <abstractions/ubuntu-helpers>
|
||||
|
||||
#include <abstractions/kde>
|
||||
abi <abi/3.0>,
|
||||
|
||||
include <abstractions/kde>
|
||||
/usr/bin/kde4-config Cx -> sanitized_helper,
|
||||
|
||||
@@ -1,9 +1,11 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# for mailto:
|
||||
#include <abstractions/ubuntu-email>
|
||||
#include <abstractions/ubuntu-console-email>
|
||||
include <abstractions/ubuntu-email>
|
||||
include <abstractions/ubuntu-console-email>
|
||||
|
||||
# Terminals for using console applications. These abstractions should ideally
|
||||
# have 'ix' to restrct access to what only firefox is allowed to do
|
||||
#include <abstractions/ubuntu-gnome-terminal>
|
||||
include <abstractions/ubuntu-gnome-terminal>
|
||||
|
||||
@@ -1,9 +1,11 @@
|
||||
# vim:syntax=apparmor
|
||||
# Users of this abstraction need to #include the ubuntu-helpers abstraction
|
||||
# Users of this abstraction need to include the ubuntu-helpers abstraction
|
||||
# in the toplevel profile. Eg:
|
||||
# #include <abstractions/ubuntu-helpers>
|
||||
# include <abstractions/ubuntu-helpers>
|
||||
|
||||
#include <abstractions/X>
|
||||
abi <abi/3.0>,
|
||||
|
||||
include <abstractions/X>
|
||||
|
||||
# Pulseaudio
|
||||
/usr/bin/pulseaudio Pixr,
|
||||
@@ -13,10 +15,9 @@
|
||||
/usr/bin/gimp* Cxr -> sanitized_helper,
|
||||
/usr/bin/shotwell Cxr -> sanitized_helper,
|
||||
/usr/bin/digikam Cxr -> sanitized_helper,
|
||||
/usr/bin/f-spot Cxr -> sanitized_helper,
|
||||
/usr/bin/gwenview Cxr -> sanitized_helper,
|
||||
|
||||
#include <abstractions/ubuntu-media-players>
|
||||
include <abstractions/ubuntu-media-players>
|
||||
owner @{HOME}/.adobe/ w,
|
||||
owner @{HOME}/.adobe/** rw,
|
||||
owner @{HOME}/.macromedia/ w,
|
||||
@@ -25,18 +26,8 @@
|
||||
/usr/bin/lpstat Cxr -> sanitized_helper,
|
||||
/usr/bin/lpr Cxr -> sanitized_helper,
|
||||
|
||||
# npviewer
|
||||
/usr/lib/nspluginwrapper/i386/linux/npviewer{,.bin} ixr,
|
||||
/var/lib/ r,
|
||||
/var/lib/**/*.so mr,
|
||||
/usr/bin/setarch ixr,
|
||||
|
||||
# Bittorrent clients
|
||||
#include <abstractions/ubuntu-bittorrent-clients>
|
||||
|
||||
# Mozplugger
|
||||
/etc/mozpluggerrc r,
|
||||
/usr/bin/mozplugger-helper Cxr -> sanitized_helper,
|
||||
include <abstractions/ubuntu-bittorrent-clients>
|
||||
|
||||
# Archivers
|
||||
/usr/bin/ark Cxr -> sanitized_helper,
|
||||
@@ -45,16 +36,10 @@
|
||||
/usr/local/lib{,32,64}/*.so* mr,
|
||||
|
||||
# News feed readers
|
||||
#include <abstractions/ubuntu-feed-readers>
|
||||
|
||||
# Googletalk
|
||||
/opt/google/talkplugin/*.so mr,
|
||||
/opt/google/talkplugin/lib/*.so mr,
|
||||
/opt/google/talkplugin/GoogleTalkPlugin ixr,
|
||||
owner @{HOME}/.config/google-googletalkplugin/** rw,
|
||||
include <abstractions/ubuntu-feed-readers>
|
||||
|
||||
# If we allow the above, nvidia based systems will also need this
|
||||
#include <abstractions/nvidia>
|
||||
include <abstractions/nvidia>
|
||||
|
||||
# Virus scanners
|
||||
/usr/bin/clamscan Cx -> sanitized_helper,
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
#
|
||||
# Plugins/helpers
|
||||
#
|
||||
@@ -13,4 +15,4 @@
|
||||
|
||||
# Since all the ubuntu-browsers.d abstractions need this, just include it
|
||||
# here
|
||||
#include <abstractions/ubuntu-helpers>
|
||||
include <abstractions/ubuntu-helpers>
|
||||
|
||||
@@ -1,7 +1,9 @@
|
||||
# vim:syntax=apparmor
|
||||
# Users of this abstraction need to #include the ubuntu-helpers abstraction
|
||||
# Users of this abstraction need to include the ubuntu-helpers abstraction
|
||||
# in the toplevel profile. Eg:
|
||||
# #include <abstractions/ubuntu-helpers>
|
||||
# include <abstractions/ubuntu-helpers>
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# Openoffice.org
|
||||
/usr/bin/ooffice Cxr -> sanitized_helper,
|
||||
@@ -22,7 +24,3 @@
|
||||
# PDFs
|
||||
/usr/bin/evince Cxr -> sanitized_helper,
|
||||
/usr/bin/okular Cxr -> sanitized_helper,
|
||||
|
||||
owner @{HOME}/.adobe/** rw,
|
||||
/opt/Adobe/Reader9/bin/acroread Cxr -> sanitized_helper,
|
||||
/opt/Adobe/Reader9/** r,
|
||||
|
||||
@@ -1,7 +1,9 @@
|
||||
# vim:syntax=apparmor
|
||||
# Users of this abstraction need to #include the ubuntu-helpers abstraction
|
||||
# Users of this abstraction need to include the ubuntu-helpers abstraction
|
||||
# in the toplevel profile. Eg:
|
||||
# #include <abstractions/ubuntu-helpers>
|
||||
# include <abstractions/ubuntu-helpers>
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# Text editors (It's All Text [https://addons.mozilla.org/en-US/firefox/addon/4125])
|
||||
/usr/bin/emacsclient.emacs-snapshot Cxr -> sanitized_helper,
|
||||
|
||||
@@ -1,16 +1,15 @@
|
||||
# vim:syntax=apparmor
|
||||
# Users of this abstraction need to #include the ubuntu-helpers abstraction
|
||||
# Users of this abstraction need to include the ubuntu-helpers abstraction
|
||||
# in the toplevel profile. Eg:
|
||||
# #include <abstractions/ubuntu-helpers>
|
||||
# include <abstractions/ubuntu-helpers>
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
||||
# Apport
|
||||
/usr/bin/apport-bug Cx -> sanitized_helper,
|
||||
|
||||
# Package installation
|
||||
/usr/bin/apturl Cxr -> sanitized_helper,
|
||||
/usr/bin/gnome-codec-install Cxr -> sanitized_helper,
|
||||
/usr/lib/gstreamer0.10/gstreamer-0.10/gst-plugin-scanner ix,
|
||||
/usr/lib/@{multiarch}/gstreamer0.10/gstreamer-0.10/gst-plugin-scanner ix,
|
||||
/usr/share/software-center/software-center Cxr -> sanitized_helper,
|
||||
|
||||
# Input Methods
|
||||
@@ -29,10 +28,7 @@
|
||||
/usr/lib/mozilla/kmozillahelper Cxr -> sanitized_helper,
|
||||
|
||||
# Exo-aware applications
|
||||
/usr/bin/exo-open ixr,
|
||||
/usr/lib/@{multiarch}/xfce4/exo-1/exo-helper-1 ixr,
|
||||
/etc/xdg/xdg-xubuntu/xfce4/helpers.rc r,
|
||||
/etc/xdg/xfce4/helpers.rc r,
|
||||
include <abstractions/exo-open>
|
||||
|
||||
# unity webapps integration. Could go in its own abstraction
|
||||
owner /run/user/*/dconf/user rw,
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user