adjust AppArmor profile installation
Sascha Steinbiss
7 years ago
0 | #include <tunables/global> | |
1 | ||
2 | /usr/bin/onioncircuits { | |
3 | #include <abstractions/base> | |
4 | #include <abstractions/gnome> | |
5 | #include <abstractions/ibus> | |
6 | #include <abstractions/nameservice> | |
7 | #include <abstractions/python> | |
8 | ||
9 | # Why are these not in abstractions/python? | |
10 | /usr/lib{,32,64}/python{2,3}.[0-9]/__pycache__/ rw, | |
11 | /usr/lib{,32,64}/python{2,3}.[0-9]/__pycache__/* rw, | |
12 | /usr/lib{,32,64}/python{2,3}.[0-9]/**/__pycache__/ rw, | |
13 | /usr/lib{,32,64}/python{2,3}.[0-9]/**/__pycache__/* rw, | |
14 | /usr/lib{,32,64}/python{2,3}/**/__pycache__/ rw, | |
15 | /usr/lib{,32,64}/python{2,3}/**/__pycache__/* rw, | |
16 | ||
17 | /usr/bin/ r, | |
18 | /usr/bin/onioncircuits r, | |
19 | /usr/share/xml/iso-codes/** r, | |
20 | ||
21 | deny /etc/machine-id r, | |
22 | ||
23 | # Accessibility support | |
24 | owner /{,var/}run/user/*/at-spi2-*/ rw, | |
25 | owner /{,var/}run/user/*/at-spi2-*/** rw, | |
26 | } |
0 | #include <tunables/global> | |
1 | ||
2 | /usr/bin/onioncircuits { | |
3 | #include <abstractions/base> | |
4 | #include <abstractions/gnome> | |
5 | #include <abstractions/ibus> | |
6 | #include <abstractions/nameservice> | |
7 | #include <abstractions/python> | |
8 | ||
9 | # Why are these not in abstractions/python? | |
10 | /usr/lib{,32,64}/python{2,3}.[0-9]/__pycache__/ rw, | |
11 | /usr/lib{,32,64}/python{2,3}.[0-9]/__pycache__/* rw, | |
12 | /usr/lib{,32,64}/python{2,3}.[0-9]/**/__pycache__/ rw, | |
13 | /usr/lib{,32,64}/python{2,3}.[0-9]/**/__pycache__/* rw, | |
14 | /usr/lib{,32,64}/python{2,3}/**/__pycache__/ rw, | |
15 | /usr/lib{,32,64}/python{2,3}/**/__pycache__/* rw, | |
16 | ||
17 | /usr/bin/ r, | |
18 | /usr/bin/onioncircuits r, | |
19 | /usr/share/xml/iso-codes/** r, | |
20 | ||
21 | deny /etc/machine-id r, | |
22 | ||
23 | # Accessibility support | |
24 | owner /{,var/}run/user/*/at-spi2-*/ rw, | |
25 | owner /{,var/}run/user/*/at-spi2-*/** rw, | |
26 | } |
0 | onioncircuits (0.4-4) UNRELEASED; urgency=medium | |
1 | ||
2 | [ Ulrike Uhlig ] | |
3 | * Add AppArmor profile for Onioncircuits. | |
4 | ||
5 | -- Sascha Steinbiss <satta@debian.org> Wed, 22 Mar 2017 14:50:09 +0100 | |
6 | ||
0 | 7 | onioncircuits (0.4-3) unstable; urgency=medium |
1 | 8 | |
2 | 9 | * Do not use dbus-launch to set up dbus environment. |
3 | 3 | Maintainer: Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org> |
4 | 4 | Uploaders: Sascha Steinbiss <satta@debian.org> |
5 | 5 | Build-Depends: debhelper (>= 9), |
6 | dh-apparmor, | |
6 | 7 | dh-python, |
7 | 8 | python3-all, |
8 | 9 | python3-setuptools, |
6 | 6 | dh $@ --with python3 --buildsystem=pybuild |
7 | 7 | |
8 | 8 | override_dh_install: |
9 | install -m 644 debian/apparmor/usr.bin.onioncircuits debian/onioncircuits/etc/apparmor.d/usr.bin.onioncircuits | |
9 | install -m 644 -D debian/apparmor/usr.bin.onioncircuits debian/onioncircuits/etc/apparmor.d/usr.bin.onioncircuits | |
10 | 10 | dh_apparmor --profile-name=usr.bin.onioncircuits -ponioncircuits |
11 | 11 | |
12 | 12 | override_dh_installman: |