summaryrefslogtreecommitdiffstats
path: root/config/chroot_local-includes/etc/apparmor.d/usr.bin.onioncircuits
blob: 61c0cb6bc937b7374c6fdd1e52cc8b5224cd8b59 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
#include <tunables/global>

/usr/bin/onioncircuits {
  #include <abstractions/base>
  #include <abstractions/gnome>
  #include <abstractions/ibus>
  #include <abstractions/nameservice>
  #include <abstractions/python>

  # Why are these not in abstractions/python?
  /usr/lib{,32,64}/python{2,3}.[0-9]/__pycache__/ rw,
  /usr/lib{,32,64}/python{2,3}.[0-9]/__pycache__/* rw,
  /usr/lib{,32,64}/python{2,3}.[0-9]/**/__pycache__/ rw,
  /usr/lib{,32,64}/python{2,3}.[0-9]/**/__pycache__/* rw,
  /usr/lib{,32,64}/python{2,3}/**/__pycache__/ rw,
  /usr/lib{,32,64}/python{2,3}/**/__pycache__/* rw,

  /usr/bin/ r,
  /usr/bin/onioncircuits r,
  /usr/share/xml/iso-codes/** r,

  deny /etc/machine-id r,

  # Accessibility support
  owner /{,var/}run/user/*/at-spi2-*/ rw,
  owner /{,var/}run/user/*/at-spi2-*/** rw,
}