-# Last Modified: Thu Jan 19 09:45:04 2012
-#include <tunables/global>
-
+# Last Modified: Fri Jan 20 21:18:46 2012
/home/harvie/Work/bash-offline.sh {
- /** rixwmkl,
+ deny capability chown,
+ deny capability net_raw,
+ deny capability setgid,
+ deny capability setuid,
+ deny capability sys_ptrace,
+ deny capability sys_resource,
+
+
+
+ /** mrwlkix,
+
}
-# Last Modified: Wed Jan 18 13:58:35 2012
+# Last Modified: Sun Jan 22 20:02:45 2012
# This profile is made for users that are building
# AUR packages from untrusted PKGBUILDs often
#include <abstractions/bash>
#include <abstractions/consoles>
- /** rix,
- /etc/** r,
+
+
+ / rix,
+ /** rkix,
/home/*/.ccache/** rwix,
/home/*/{Temp,Work/PKGBUILDs}/** rw,
/tmp/** rwkix,
-# Last Modified: Wed Jan 18 12:29:15 2012
+# Last Modified: Thu Jan 19 19:56:19 2012
# ------------------------------------------------------------------
#
# Copyright (C) 2002-2005 Novell/SUSE
/opt/MozillaFirefox/bin/firefox.sh Px,
/opt/kde/share/** r,
/opt/kde3/bin/kde-config mrix,
+ /sys/devices/system/cpu/* r,
owner /tmp/** rwlk,
/tmp/** m,
/usr/X11R6/lib/Acrobat*/Resource/Font/* r,
-# Last Modified: Wed Jan 18 18:05:11 2012
+# Last Modified: Fri Jan 20 21:18:46 2012
# Author: Thomas Mudrunka
#include <tunables/global>
-/usr/lib/chromium/chromium {
+/usr/lib/chromium/chromium flags=(complain) {
#include <abstractions/audio>
#include <abstractions/base>
+ #include <abstractions/bash>
#include <abstractions/fonts>
#include <abstractions/freedesktop.org>
#include <abstractions/gnome>
/bin/ps mrix,
/dev/shm/* rw,
/etc/** r,
- /home/*/* r,
- /home/*/.adobe/**/ rw,
+ /home/*/* rwk,
+ /home/*/.adobe/** rw,
/home/*/.cache/chromium/** rw,
/home/*/.cups/* r,
/home/*/.icons/** r,
+ /home/*/.local/share/** r,
/home/*/.macromedia/** rw,
- /home/*/.mozilla/** r,
+ /home/*/.mozilla/** rwk,
/home/*/.pki/** rwk,
/home/*/.themes/** r,
+ /home/*/Desktop/ r,
+ /home/*/Desktop/* rw,
+ /home/*/Downloads/ r,
/home/*/Downloads/** rw,
/home/*/Work/GIT/plugins/chrome-extensions/** r,
/home/*/private/dotfiles/.config/chromium/** mrwk,
/proc/ r,
/proc/** rw,
/sys/** r,
- /tmp/* r,
+ owner /tmp/** lk,
+ /tmp/** rw,
+ /usr/bin/gpg mrix,
+ /usr/bin/xdg-open rix,
+ /usr/bin/xdg-settings rix,
/usr/lib/chromium/chromium rix,
/usr/lib/chromium/chromium-sandbox rix,
+ /usr/lib/chromium/nacl_helper_bootstrap rix,
/usr/lib/lib*so* mr,
+ /usr/lib/totem/totem-plugin-viewer rix,
/var/db/nscd/* r,
/var/tmp/* rw,