Dodany przez: /usr/lib64/chromium-browser/chrome, 12:04 20-08-2018

Nowy Pobierz
  1. # Last Modified: Thu Jan 11 16:16:07 2018
  2. #include <tunables/global>
  3.  
  4. /usr/lib64/chromium-browser/chrome {
  5.   #include <abstractions/X>
  6.   #include <abstractions/audio>
  7.   #include <abstractions/base>
  8.   #include <abstractions/bash>
  9.   #include <abstractions/consoles>
  10.   #include <abstractions/dbus-session>
  11.   #include <abstractions/fonts>
  12.   #include <abstractions/gnome>
  13.   #include <abstractions/java>
  14.   #include <abstractions/nvidia>
  15.   #include <abstractions/user-tmp>
  16.  
  17.   capability sys_admin,
  18.   capability sys_chroot,
  19.  
  20.   network inet dgram,
  21.   network inet stream,
  22.   network inet6 dgram,
  23.   network inet6 stream,
  24.  
  25.   signal receive set=abrt peer=/usr/lib64/chromium-browser/chrome,
  26.   signal receive set=kill peer=/usr/lib64/chromium-browser/chrome,
  27.   signal receive set=term peer=/usr/lib64/chromium-browser/chrome,
  28.   signal receive set=term peer=unconfined,
  29.   signal send set=abrt peer=/usr/lib64/chromium-browser/chrome,
  30.   signal send set=kill peer=/usr/lib64/chromium-browser/chrome,
  31.   signal send set=term peer=/usr/lib64/chromium-browser/chrome,
  32.  
  33.   deny /etc/ r,
  34.   deny /selinux/ r,
  35.   deny /sys/modules/ mrwlx,
  36.   deny /usr/bin/bug-buddy x,
  37.   deny owner @{HOME}/.mozilla/plugins/ r,
  38.  
  39.   /bin/bash ix,
  40.   /bin/bash ix,
  41.   /bin/bash rix,
  42.   /bin/bzip2 rix,
  43.   /bin/cat rix,
  44.   /bin/dirname rix,
  45.   /bin/head rix,
  46.   /bin/readlink rix,
  47.   /bin/sed rix,
  48.   /bin/which rix,
  49.   /dev/ r,
  50.   /dev/shm/.com.google.Chrome* rw,
  51.   /dev/video0 r,
  52.   /dev/video1 r,
  53.   /dev/video3 r,
  54.   /etc/fstab r,
  55.   /etc/gai.conf r,
  56.   /etc/gentoo-release r,
  57.   /etc/group r,
  58.   /etc/host.conf r,
  59.   /etc/hosts r,
  60.   /etc/lsb-release r,
  61.   /etc/man_db.conf r,
  62.   /etc/mtab r,
  63.   /etc/nsswitch.conf r,
  64.   /etc/os-release r,
  65.   /etc/passwd r,
  66.   /etc/python2.7/sitecustomize.py r,
  67.   /etc/resolv.conf r,
  68.   /etc/udev/udev.conf r,
  69.   /opt/Adobe/flash-player/flash-plugin/libflashplayer.so mr,
  70.   /usr/lib64/chromium-browser/** r,
  71.   /usr/lib64/chromium-browser/*.so mr,
  72.   /opt/google/*/PepperFlash/libpepflashplayer.so mr,
  73.   /usr/lib64/chromium-browser/chrome mrix,
  74.   /usr/lib64/chromium-browser/extensions/ mrw,
  75.  
  76.   /proc/ r,
  77.   /proc/cpuinfo r,
  78.   /proc/filesystems r,
  79.   /proc/meminfo r,
  80.   /proc/sys/kernel/shmmax r,
  81.   /proc/sys/kernel/yama/ptrace_scope r,
  82.   /proc/sys/net/ipv4/tcp_fastopen r,
  83.   /proc/vmstat r,
  84.   /sys/ r,
  85.   /sys/** r,
  86.   /sys/block/sda/sda[0-9]/size r,
  87.   /sys/block/sda/sda[0-9]/uevent r,
  88.   /sys/devices/pci[0-9]*/**/class r,
  89.   /sys/devices/pci[0-9]*/**/device r,
  90.   /sys/devices/pci[0-9]*/**/irq r,
  91.   /sys/devices/pci[0-9]*/**/resource r,
  92.   /sys/devices/pci[0-9]*/**/vendor r,
  93.   /tmp/ r,
  94.   /usr/bin/col rix,
  95.   /usr/bin/find rix,
  96.   /usr/bin/getopt rix,
  97.   /usr/bin/groff rix,
  98.   /usr/bin/grotty rix,
  99.   /usr/bin/locale rix,
  100.   /usr/bin/lsb_release rix,
  101.   /usr/bin/man rix,
  102.   /usr/bin/nroff r,
  103.   /usr/bin/nroff rix,
  104.   /usr/bin/preconv rix,
  105.   /usr/bin/python2.7 r,
  106.   /usr/bin/smplayer PUx,
  107.   /usr/bin/tbl rix,
  108.   /usr/bin/troff rix,
  109.   /usr/bin/which rix,
  110.   /usr/bin/xdg-open PUx,
  111.   /usr/bin/xdg-settings PUx,
  112.   /usr/include/python2.7/pyconfig.h r,
  113.   /usr/lib/jvm/**/jre/lib/amd64/IcedTeaPlugin.so mr,
  114.   /usr/lib/mozilla/plugins/gecko-mediaplayer-*.so mr,
  115.   /usr/lib/totem/totem-plugin-viewer Px,
  116.   /usr/lib/x86_64-linux-gnu/gtk-2.0/*/immodules/*.so mr,
  117.   /usr/lib/x86_64-linux-gnu/pango/*/modules/pango-*.so mr,
  118.   /usr/lib64/chromium-browser/chrome mrix,
  119.   /usr/lib64/chromium-browser/chromium-launcher.sh mrix,
  120.   /usr/lib64/chromium-browser/chromium-launcher.sh r,
  121.   /usr/libexec/man-db/manconv rix,
  122.   /usr/lib{,32,64}/** mr,
  123.   /usr/local/lib/python2.7/dist-packages/ r,
  124.   /usr/share/X11/XErrorDB r,
  125.   /usr/share/glib-2.0/schemas/gschemas.compiled r,
  126.   /usr/share/gvfs/remote-volume-monitors/ r,
  127.   /usr/share/gvfs/remote-volume-monitors/* r,
  128.   /usr/share/icons/ r,
  129.   /usr/share/icons/** r,
  130.   /usr/share/mime/** r,
  131.   /usr/share/misc/pci.ids r,
  132.   /usr/share/pixmaps/ r,
  133.   /usr/share/pyshared/* r,
  134.   /usr/share/themes/** r,
  135.   /var/cache/man/cat1/cat2QxLQ2 w,
  136.   /var/cache/man/cat1/catAduaPc w,
  137.   /var/cache/man/cat1/catalnbB4 w,
  138.   /var/cache/man/cat1/catv8PgNE w,
  139.   /var/cache/man/index.db rk,
  140.   /var/cache/man/pl/index.db rk,
  141.   /var/tmp/ r,
  142.   /var/tmp/* rw,
  143.   /{,var/}run/resolvconf/resolv.conf r,
  144.   /{,var/}run/shm/.com.google.Chrome.* rw,
  145.   /{,var/}run/shm/com.google.Chrome.shmem.* rw,
  146.   /{,var/}run/udev/queue.bin r,
  147.   /{run,dev}/shm/pulse-shm* rw,
  148.   @{PROC}/@{pid}/auxv r,
  149.   @{PROC}/@{pid}/cmdline r,
  150.   @{PROC}/@{pid}/environ r,
  151.   @{PROC}/@{pid}/fd/ r,
  152.   @{PROC}/@{pid}/io r,
  153.   @{PROC}/@{pid}/maps r,
  154.   @{PROC}/@{pid}/mounts r,
  155.   @{PROC}/@{pid}/oom_score_adj w,
  156.   @{PROC}/@{pid}/setgroups w,
  157.   @{PROC}/@{pid}/stat r,
  158.   @{PROC}/@{pid}/statm r,
  159.   @{PROC}/@{pid}/status r,
  160.   @{PROC}/@{pid}/task/ r,
  161.   @{PROC}/@{pid}/task/**/syscall r,
  162.   @{PROC}/@{pid}/task/[0-9]*/stat r,
  163.   owner /dev/shm/.org.chromium.Chromium.* rw,
  164.   owner /tmp/** rwk,
  165.   owner /usr/lib{,32,64}/** mrw,
  166.   owner /{run,dev}/shm/pulse-shm* k,
  167.   owner @{HOME}/ r,
  168.   owner @{HOME}/* r,
  169.   owner @{HOME}/.ICEauthority r,
  170.   owner @{HOME}/.Xauthority r,
  171.   owner @{HOME}/.cache/chromium/ rw,
  172.   owner @{HOME}/.cache/chromium/** rw,
  173.   owner @{HOME}/.cache/dconf/user rw,
  174.   owner @{HOME}/.config/chromium/ rwk,
  175.   owner @{HOME}/.config/chromium/ rwl,
  176.   owner @{HOME}/.config/chromium/** mrwk,
  177.   owner @{HOME}/.config/chromium/** mrwk,
  178.   owner @{HOME}/.config/dconf/user r,
  179.   owner @{HOME}/.config/gtk-3.0/gtk.css r,
  180.   owner @{HOME}/.config/gtk-3.0/settings.ini r,
  181.   owner @{HOME}/.config/ibus/bus/ w,
  182.   owner @{HOME}/.config/pulse/client.conf r,
  183.   owner @{HOME}/.config/user-dirs.dirs r,
  184.   owner @{HOME}/.fontconfig/* r,
  185.   owner @{HOME}/.gksu.lock r,
  186.   owner @{HOME}/.goutputstream-* r,
  187.   owner @{HOME}/.gtk-bookmarks r,
  188.   owner @{HOME}/.icons/ r,
  189.   owner @{HOME}/.local/share/icons/ r,
  190.   owner @{HOME}/.local/share/icons/** r,
  191.   owner @{HOME}/.local/share/mime/* r,
  192.   owner @{HOME}/.local/share/recently-used.xbel* rw,
  193.   owner @{HOME}/.local/share/sddm/xorg-session.log w,
  194.   owner @{HOME}/.nv/GLCache/ r,
  195.   owner @{HOME}/.nv/GLCache/** rwk,
  196.   owner @{HOME}/.nv/nvidia-application-profile-globals-rc r,
  197.   owner @{HOME}/.pki/nssdb/ rw,
  198.   owner @{HOME}/.pki/nssdb/** rwk,
  199.   owner @{HOME}/.pki/nssdb/*.db rwk,
  200.   owner @{HOME}/.pki/nssdb/pkcs11.txt rw,
  201.   owner @{HOME}/.pulse-cookie rwk,
  202.   owner @{HOME}/.thumbnails/normal/* r,
  203.   owner @{HOME}/.xsession-errors r,
  204.   owner @{HOME}/Desktop/ r,
  205.   owner @{HOME}/Desktop/* rw,
  206.   owner @{HOME}/Pobrane/ r,
  207.   owner @{HOME}/Pobrane/** rw,
  208.   owner @{HOME}/libpeerconnection.log w,
  209.   owner @{PROC}/@{pid}//oom_score_adj w,
  210.   owner @{PROC}/@{pid}/gid_map rw,
  211.   owner @{PROC}/@{pid}/uid_map rw,
  212.  
  213.  
  214.   profile /opt/google/*/xdg-settings {
  215.     /bin/dash r,
  216.     /bin/grep rix,
  217.     /bin/readlink rix,
  218.     /bin/sed rix,
  219.     /bin/which rix,
  220.     /dev/null w,
  221.     /etc/gnome/defaults.list r,
  222.     /etc/ld.so.cache r,
  223.     /etc/locale.alias r,
  224.     /lib/x86_64-linux-gnu/ld-*.so r,
  225.     /lib/x86_64-linux-gnu/libc-*.so mr,
  226.     /lib/x86_64-linux-gnu/libdl-*.so mr,
  227.     /lib/x86_64-linux-gnu/libm-*.so mr,
  228.     /lib/x86_64-linux-gnu/libselinux.so.* mr,
  229.     /lib{,32,64}/ r,
  230.     /lib{,32,64}/** mr,
  231.     /opt/google/chrome/xdg-settings r,
  232.     /proc/filesystems r,
  233.     /usr/**/lib{,32,64}/ mr,
  234.     /usr/**/lib{,32,64}/** mr,
  235.     /usr/**/share/ r,
  236.     /usr/**/share/** r,
  237.     /usr/bin/basename rix,
  238.     /usr/bin/cut rix,
  239.     /usr/bin/gawk rix,
  240.     /usr/bin/mawk rix,
  241.     /usr/bin/xdg-mime rix,
  242.     /usr/bin/xdg-open PUx,
  243.     /usr/bin/xdg-settings PUx,
  244.     /usr/lib/locale/** r,
  245.     /usr/lib/x86_64-linux-gnu/gconv/gconv-modules.cache r,
  246.     /usr/lib{,32,64}/ r,
  247.     /usr/lib{,32,64}/** mr,
  248.     /usr/local/bin/qtorrent PUx,
  249.     /usr/local/bin/skyper PUx,
  250.     /usr/share/ r,
  251.     /usr/share/** r,
  252.     owner /proc/*/maps r,
  253.     owner @{HOME}/.local/share/applications/google-chrome.desktop r,
  254.     owner @{HOME}/.local/share/applications/mimeapps.list r,
  255.  
  256.   }
  257. }
  258.  

Źródło:

Ostatnie wpisy

Linki

Funkcje