Advertisement
big_bum

apparmor profile skype4

Jun 24th, 2012
288
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Bash 1.71 KB | None | 0 0
  1. # Last Modified: Sun Jun 24 14:57:04 2012
  2. # Last Modified: Mon Oct 26 13:29:13 2009
  3. # REPOSITORY: http://apparmor.test.opensuse.org/backend/api draglor 53
  4. # Additional profiling based on work by Андрей Калинин, LP: #226624
  5. #include <tunables/global>
  6. /usr/bin/skype {
  7.   #include <abstractions/audio>
  8.   #include <abstractions/base>
  9.   #include <abstractions/fonts>
  10.   #include <abstractions/freedesktop.org>
  11.   #include <abstractions/kde>
  12.   #include <abstractions/gnome>
  13.   #include <abstractions/dbus-session>
  14.   #include <abstractions/nameservice>
  15.   #include <abstractions/nvidia>
  16.   #include <abstractions/user-tmp>
  17.   #include <abstractions/X>
  18.  
  19.   # are these needed?
  20.   /proc/*/cmdline r,
  21.   /dev/video* mrw,
  22.   /dev/ r,
  23.   /var/cache/libx11/compose/* r,
  24.   /dev/shm/pulse* rwm,
  25.  
  26.   # should this be in a separate KDE abstraction?
  27.   @{HOME}/.kde/share/config/kioslaverc r,
  28.  
  29.   # Shared data:
  30.   /usr/share/fonts/** mr,
  31.   /usr/share/skype/** mr,
  32.   /usr/share/ca-certificates/** mr,
  33.  
  34.   # Libraries:
  35.   /usr/lib/pango/*.so mr,
  36.  
  37.   # System information
  38.   /sys/devices/system/cpu/ r,
  39.   /sys/devices/system/cpu/** r,
  40.  
  41.   /usr/bin/skype mr,
  42.   /usr/share/skype/** kr,
  43.   /usr/share/skype/sounds/*.wav kr,
  44.   /etc/ssl/certs/ r,
  45.   /etc/ssl/certs/** r,
  46.   /etc/xdg/Trolltech.conf kr,
  47.  
  48.   @{HOME}/.Skype/   rw,
  49.   @{HOME}/.Skype/** krw,
  50.   @{HOME}/.config/* kr,
  51.  
  52.   # Shouldn't look there sweetie!!!
  53.   deny @{HOME}/.mozilla/ r,
  54.   deny @{HOME}/.mozilla/*/ r,
  55.   deny @{HOME}/.mozilla/*/*/ r,
  56.   deny @{HOME}/.mozilla/*/*/bookmarkbackups/ r,
  57.   deny @{HOME}/.mozilla/*/*/chrome/ r,
  58.   deny @{HOME}/.mozilla/*/*/extensions/ r,
  59.   deny @{HOME}/.mozilla/*/*/prefs.js r,
  60.   deny /etc/passwd r,
  61. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement