# Note: This profile does not specify an attachment path because it is # intended to be used only via "Px -> lsb_release" exec transitions from # other profiles. We want to confine the lsb_release(1) utility when it # is invoked from other confined applications, but not when it is used # in regular (unconfined) shell scripts or run directly by the user. #include <tunables/global> # Do not attach to /usr/bin/lsb_release by default profile lsb_release { #include <abstractions/base> #include <abstractions/python> owner @{PROC}/@{pid}/fd/ r, /dev/tty rw, /usr/bin/lsb_release r, /usr/bin/python3.[0-9] mr, /etc/debian_version r, /etc/default/apport r, /etc/dpkg/origins/** r, /etc/lsb-release r, /etc/lsb-release.d/ r, /{usr/,}bin/bash ixr, /{usr/,}bin/dash ixr, /usr/bin/basename ixr, /usr/bin/dpkg-query ixr, /usr/bin/getopt ixr, /usr/bin/sed ixr, /usr/bin/tr ixr, # TODO - many more permissions needed for this to work deny /usr/bin/apt-cache x, /usr/bin/ r, /usr/include/python*/pyconfig.h r, /usr/share/distro-info/** r, /usr/share/dpkg/** r, /usr/share/terminfo/** r, /var/lib/dpkg/** r, # file_inherit deny /tmp/gtalkplugin.log w, # Site-specific additions and overrides. See local/README for details. #include <local/lsb_release> }
Name | Type | Size | Permission | Actions |
---|---|---|---|---|
abi | Folder | 0755 |
|
|
abstractions | Folder | 0755 |
|
|
disable | Folder | 0755 |
|
|
force-complain | Folder | 0755 |
|
|
local | Folder | 0755 |
|
|
tunables | Folder | 0755 |
|
|
lsb_release | File | 1.28 KB | 0644 |
|
nvidia_modprobe | File | 1.08 KB | 0644 |
|
sbin.dhclient | File | 3.42 KB | 0644 |
|
usr.bin.evince | File | 10.82 KB | 0644 |
|
usr.bin.firefox | File | 9.95 KB | 0644 |
|
usr.bin.man | File | 3.13 KB | 0644 |
|
usr.lib.libreoffice.program.oosplash | File | 1.48 KB | 0644 |
|
usr.lib.libreoffice.program.senddoc | File | 1.2 KB | 0644 |
|
usr.lib.libreoffice.program.soffice.bin | File | 10.4 KB | 0644 |
|
usr.lib.libreoffice.program.xpdfimport | File | 1.02 KB | 0644 |
|
usr.lib.snapd.snap-confine.real | File | 28.76 KB | 0644 |
|
usr.sbin.cups-browsed | File | 540 B | 0644 |
|
usr.sbin.cupsd | File | 5.66 KB | 0644 |
|
usr.sbin.ippusbxd | File | 672 B | 0644 |
|
usr.sbin.mysqld | File | 1.96 KB | 0644 |
|
usr.sbin.rsyslogd | File | 1.54 KB | 0644 |
|
usr.sbin.tcpdump | File | 1.45 KB | 0644 |
|