# Last Modified: Sat Jul 13 15:32:02 2013
#include <tunables/global>
@{MOZ_LIBDIR}=/usr/lib64/firefox
/usr/lib64/firefox/plugin-container {
#include <abstractions/base>
#include <abstractions/private-files>
#include <abstractions/private-files-strict>
#include <abstractions/X>
#include <abstractions/gnome>
#include <abstractions/audio>
#include <abstractions/nvidia>
#include <abstractions/fonts>
#include <abstractions/freedesktop.org>
#include <abstractions/nameservice>
#include <abstractions/user-tmp>
@{MOZ_LIBDIR}/ r,
@{MOZ_LIBDIR}/** mixr,
/ r,
/**/ r,
/lib{,32,64}/ r,
/lib{,32,64}/** mr,
## /usr/lib64/firefox/plugin-container mr,
# /bin/bash ixr,
deny /usr/bin/bug-buddy mrxwkl,
/etc/nsswitch.conf r,
/etc/resolv.conf r,
/etc/adobe/mms.cfg r,
/etc/ssl/openssl.cnf r,
/sys/devices/system/cpu/online r,
/sys/devices/system/cpu/present r,
/proc/sys/vm/overcommit_memory r,
/sys/devices/system/cpu/cpu1/cpufreq/scaling_cur_freq r,
/sys/devices/system/cpu/cpu1/cpufreq/cpuinfo_max_freq r,
/sys/devices/**/config r,
/sys/bus/pci/devices/ r,
@{PROC}/scsi/scsi r,
/etc/hosts r,
/etc/host.conf r,
/etc/passwd r,
/etc/ssl/certs/java/cacerts r,
/etc/lsb-release r,
/etc/ld.so.cache r,
/etc/nsswitch.conf r,
/etc/resolv.conf r,
/etc/timezone r,
/etc/mtab r,
/etc/fstab r,
/bin/basename rix,
/usr/bin/md5sum rix,
/usr/bin/dirname rix,
/usr/bin/mkfifo rUx,
/usr/bin/pwd rix,
/usr/bin/tr rix,
/usr/bin/wget PUx,
/usr/bin/glxinfo PUx,
/bin/sed rix,
/bin/bash rix,
/bin/cut rix,
/bin/cat rix,
/bin/grep rix,
/bin/ln rix,
/bin/rm rix,
/bin/mktemp rix,
/bin/mkdir rix,
/bin/mv rix,
/usr/bin/flock rix,
/usr/bin/sha1sum rix,
/usr/bin/sha256sum rix,
/usr/bin/sha384sum rix,
/usr/bin/sha512sum rix,
/sbin/killall5 rix,
/usr/bin/wine rix,
/usr/bin/wine-preloader rix,
/usr/bin/wineserver rix,
/tmp/.X[0-9]*-lock r,
owner @{HOME}/.wine-pipelight/ r,
owner @{HOME}/.wine-pipelight/** mrw,
owner @{HOME}/.cache/mozilla/ r,
owner @{HOME}/.cache/mozilla/** r,
owner @{HOME}/.icedtea/cache/recently_used k,
owner @{HOME}/mm.cfg r,
owner @{HOME}/.adobe/ r,
owner @{HOME}/.adobe/** r,
owner @{HOME}/.macromedia/ r,
owner @{HOME}/.macromedia/** r,
owner @{HOME}/.compose-cache/ r,
owner @{HOME}/.compose-cache/** r,
owner @{HOME}/.config/pipelight* r,
owner @{HOME}/.config/freshwrapper-*/ r,
owner @{HOME}/.config/freshwrapper-*/** r,
owner @{HOME}/.mozilla/ r,
owner @{HOME}/.mozilla/** r,
owner @{HOME}/.mozilla/**/*.sqlite* k,
owner @{HOME}/.mozilla/**/.parentlock k,
owner @{HOME}/.mozilla/**/extensions/** mrix,
owner @{HOME}/.mozilla/**/plugins/** mr,
owner @{HOME}/.mozilla/firefox/profiles.ini r,
owner @{HOME}/.mozilla/plugins/** mr,
owner @{HOME}/.wine-pipelight/** rmixk,
owner @{HOME}/.fonts/** mr,
owner @{PROC}/[0-9]*/cmdline r,
owner @{PROC}/[0-9]*/fd/ r,
owner @{PROC}/[0-9]*/fd/* r,
owner @{PROC}/[0-9]*/maps r,
owner @{PROC}/[0-9]*/mountinfo r,
@{PROC}/[0-9]*/net/if_inet6 r,
@{PROC}/[0-9]*/net/ipv6_route r,
owner @{PROC}/[0-9]*/stat r,
owner @{PROC}/[0-9]*/statm r,
owner @{PROC}/[0-9]*/status r,
owner @{PROC}/[0-9]*/task/[0-9]*/stat r,
/opt/Adobe/flash-player/flash-plugin/libflashplayer.so mr,
/opt/google/**/PepperFlash/libpepflashplayer.so mr,
/tmp/ r,
owner /tmp/** mrw,
/var/tmp/ r,
owner /var/tmp/** mrw,
/usr/lib64/icedtea7-web/lib64/IcedTeaPlugin.so mr,
owner @{HOME}/.java/deployment/deployment.properties k,
/usr/lib64/jvm/icedtea-7/jre/bin/** ixr,
/usr/lib64/icedtea7/jre/bin/** ixr,
/usr/lib64/icedtea7-web/bin/** ixr,
/usr/lib64/icedtea7-web/lib64/ r,
/usr/lib64/icedtea7-web/lib64/*.so mr,
/usr/lib64/icedtea7-web/lib64/*/*.so mr,
/usr/lib64/icedtea7-web/lib64/*/*/*.so mr,
/usr/lib/jvm/icedtea-7/jre/lib/ r,
/usr/lib/jvm/icedtea-7/jre/lib/** r,
/usr/lib/jvm/icedtea-7/jre/lib/*/*.so mr,
/usr/lib/jvm/icedtea-7/jre/lib/*/*/*.so mr,
/usr/lib/jvm/icedtea-7/jre/bin/java mixr,
/usr/lib/jvm/icedtea-7/jre/lib/*/jvm.cfg-default r,
/usr/lib/x86_64-linux-gnu/jni/libatk-wrapper.so.* mr,
/usr/lib/x86_64-linux-gnu/gconv/SJIS.so mr,
@{HOME}/.icedtea/ r,
@{HOME}/.icedtea/** r,
@{HOME}/.icedtea/cache/** rk,
@{HOME}/ r,
@{HOME}/.config/dconf/user r,
@{HOME}/.config/ibus/bus/ w,
@{HOME}/.fontconfig/ r,
@{HOME}/.fontconfig/** r,
@{HOME}/.fonts/ r,
@{HOME}/.fonts/** r,
@{HOME}/.java/ r,
@{HOME}/.java/** r,
owner @{HOME}/.mozilla/firefox/profiles.ini r,
/usr/lib{,32,64}/ mr,
/usr/lib{,32,64}/** mr,
/usr/**/lib{,32,64}/ mr,
/usr/**/lib{,32,64}/** mr,
/usr/**/share/ r,
/usr/**/share/** r,
/usr/share/ r,
/usr/share/** r,
/usr/share/pipelight/** mrix,
/usr/share/fonts/** mr,
/usr/share/wine/** mrix,
/usr/share/wine/fonts/** mr,
}
Źródło: