#include <tunables/global>
/usr/lib64/firefox/firefox {
#include <abstractions/X>
#include <abstractions/audio>
#include <abstractions/base>
#include <abstractions/cups-client>
#include <abstractions/dbus-session>
#include <abstractions/fonts>
#include <abstractions/freedesktop.org>
#include <abstractions/gnome>
#include <abstractions/kde>
#include <abstractions/nameservice>
#include <abstractions/nvidia>
#include <abstractions/private-files>
#include <abstractions/python>
#include <abstractions/user-tmp>
# deny network,
# deny network,
deny /.suspended r,
deny /bin/bash x,
deny /boot/initrd.img* r,
deny /boot/vmlinuz* r,
deny /usr/bin/clamscan x,
deny /usr/bin/which x,
deny /usr/lib/firefox-3.6.*/** w,
deny /usr/lib/firefox-3.6.10/update.test w,
deny /usr/lib/firefox-addons/** w,
deny /usr/lib/mozilla/extensions/**/ w,
deny /usr/lib/xulrunner-*/components/*.tmp w,
deny /usr/lib/xulrunner-addons/** w,
deny /usr/lib/xulrunner-addons/extensions/**/ w,
deny /usr/share/mozilla/ w,
deny /usr/share/mozilla/extensions/**/ w,
deny /var/cache/fontconfig/ w,
audit deny @{HOME}/.gnome2_private/** mrwlk,
audit deny @{HOME}/.gnupg/** mrwlk,
audit deny @{HOME}/.ssh/** mrwlk,
/bin/ps rUx,
/bin/uname rUx,
/dev/nvidia0 rw,
/dev/nvidiactl rw,
/etc/firefox*/ r,
/etc/firefox*/** r,
/etc/fstab r,
/etc/gai.conf r,
/etc/mailcap r,
/etc/mime.types r,
/etc/mtab r,
/etc/nsswitch.conf r,
/etc/resolv.conf r,
/etc/timezone r,
/etc/wildmidi/wildmidi.cfg r,
/sbin/killall5 rix,
/sys/devices/system/cpu/present r,
/sys/devices/**/config r,
/sys/bus/pci/devices/ r,
/tmp/ r,
owner /tmp/** rwm,
/tmp/.X[0-9]*-lock r,
/usr/**/lib{,32,64}/ mr,
/usr/**/lib{,32,64}/** mr,
/usr/**/share/ r,
/usr/**/share/** r,
/usr/bin/basename rix,
/usr/bin/dirname rix,
/usr/bin/evince PUx,
/usr/bin/geany PUx,
/usr/bin/clamdscan PUx,
/usr/bin/mkfifo rUx,
/opt/Adobe/flash-player/flash-plugin/libflashplayer.so r,
/usr/ r,
/usr/bin/ r,
/usr/* rix,
/usr/bin/* rix,
/usr/bin/purple-url-handler PUx,
/usr/bin/wget PUx,
/usr/bin/axel PUx,
/usr/bin/curl PUx,
/usr/bin/gnome-terminal PUx,
/usr/local/bin/mailto PUx,
/usr/bin/pwd rix,
/usr/bin/python-wrapper PUx,
/usr/bin/smplayer PUx,
/usr/bin/steam PUx,
/usr/bin/totem PUx,
/usr/bin/tr rix,
/usr/bin/vlc PUx,
/usr/bin/which rUx,
/usr/lib64/firefox/** mrix,
/usr/lib64/firefox/plugin-container PUx,
/usr/bin/exo-open PUx,
/usr/libexec/gstreamer-0.10/gst-plugin-scanner rix,
/usr/lib64/gstreamer-1.0/gst-plugin-scanner rix,
/lib{,32,64}/ r,
/lib{,32,64}/** mr,
/usr/lib{,32,64}/ r,
/usr/lib{,32,64}/** mr,
/usr/local/bin/qtorrent PUx,
/usr/local/bin/skyper PUx,
/usr/share/ r,
/usr/share/** r,
/var/tmp/ r,
owner /var/tmp/** rm,
owner @{HOME}/ r,
owner @{HOME}/* r,
owner @{HOME}/.adobe/ r,
owner @{HOME}/.adobe/** r,
owner @{HOME}/.cache/mozilla/ rw,
owner @{HOME}/.cache/mozilla/** rw,
owner @{HOME}/.config/ r,
owner @{HOME}/.config/** r,
owner @{HOME}/.config/ibus/bus/ rw,
owner @{HOME}/.local/share/applications/defaults.list r,
owner @{HOME}/.local/share/applications/mimeinfo.cache r,
owner @{HOME}/.macromedia/ r,
owner @{HOME}/.macromedia/** r,
owner @{HOME}/.mozilla/ r,
owner @{HOME}/.mozilla/** r,
owner @{HOME}/.mozilla/firefox/** rwk,
owner @{HOME}/.icons/** r,
owner @{HOME}/.mozilla/**/*.sqlite* k,
owner @{HOME}/.mozilla/**/stylish.sqlite* rw,
owner @{HOME}/.mozilla/**/cookies.sqlite* rw,
owner @{HOME}/.mozilla/**/.parentlock k,
owner @{HOME}/.mozilla/**/extensions/** mrix,
owner @{HOME}/.mozilla/**/plugins/** mr,
owner @{HOME}/.mozilla/firefox/profiles.ini r,
owner @{HOME}/.mozilla/plugins/** mr,
owner @{HOME}/.nv/GLCache/ rk,
owner @{HOME}/.nv/GLCache/** rk,
owner @{HOME}/.nv/nvidia-application-profile-globals-rc r,
owner @{HOME}/Public/ r,
owner @{HOME}/Public/* r,
owner @{HOME}/mm.cfg rw,
owner @{HOME}/{Desktop,Downloads}/ r,
owner @{HOME}/{Desktop,Downloads}/** rw,
owner @{HOME}/.cache/gstreamer-1.0/** rw,
owner @{PROC}/[0-9]*/cmdline r,
owner @{PROC}/[0-9]*/fd/ r,
owner @{PROC}/[0-9]*/fd/* r,
owner @{PROC}/[0-9]*/maps r,
owner @{PROC}/[0-9]*/mountinfo r,
owner @{PROC}/[0-9]*/stat r,
owner @{PROC}/[0-9]*/statm r,
owner @{PROC}/[0-9]*/status r,
owner @{PROC}/[0-9]*/task/[0-9]*/stat r,
@{PROC}/[0-9]*/net/if_inet6 r,
@{PROC}/[0-9]*/net/ipv6_route r,
@{PROC}/filesystems r,
}
Źródło: