-
-
Notifications
You must be signed in to change notification settings - Fork 44
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add profile for Plank and kstart. Some KDE and containerd updates. #190
Conversation
Thank you for updating the PR. Ready for merge now. |
apparmor.d/groups/kde/kstart
Outdated
include <abstractions/fontconfig-cache-read> | ||
include <abstractions/fonts> | ||
|
||
unix (connect, send, receive) type=stream peer=(addr="@/tmp/.ICE-unix/[0-9]*"), |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Include: <abstractions/X-strict> instead.
apparmor.d/groups/kde/kstart
Outdated
/{usr/,}bin/** rPUx, | ||
/{usr/,}bin/konsole rUx, | ||
|
||
owner @{HOME}/.Xauthority r, |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
owner @{HOME}/.Xauthority r, |
Useless, once you have X-strict.
unix (connect, send, receive) type=stream peer=(addr="@/tmp/.ICE-unix/[0-9]*"), | ||
|
||
@{exec_path} mr, | ||
/{usr/,}bin/** rPUx, |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Use abstractions/app-launcher-user
instead
|
||
@{exec_path} rm, | ||
|
||
unix (send, receive, connect) type=stream peer=(addr="@/tmp/.X11-unix/X[0-9]*", label="{xorg,xkbcomp}"), |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Use X-strict
Signed-off-by: Jeroen Rijken <jeroen.rijken@xs4all.nl>
Signed-off-by: Jeroen Rijken <jeroen.rijken@xs4all.nl>
Signed-off-by: Jeroen Rijken <jeroen.rijken@xs4all.nl>
Signed-off-by: Jeroen Rijken <jeroen.rijken@xs4all.nl>
2588621
to
d042526
Compare
I fixed some issue and merged it. These profiles are useful as they can allow other not supported DE to boot. Please expect issue as these are still pretty much work in progress. |
Add profile for Plank and kstart. Some KDE and containerd updates.
This will basically push all of the AVC messages generated by kglobalaccel5 to the kstart profile for now, but the AVC messages should be easier to read.
I'm currently unable to write apparmor profiles more detailed due to some illness in my family, so you'll have to provide the following fixes yourself: