-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathusr.bin.spotify
69 lines (64 loc) · 1.82 KB
/
usr.bin.spotify
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
# Spotify 1.0.19 + Ubuntu 15.10
#include <tunables/global>
/usr/share/spotify/spotify {
#include <abstractions/base>
#include <abstractions/nameservice>
#include <abstractions/ubuntu-konsole>
capability sys_ptrace, mknod
deny /opt/Citrix/** mr,
deny /opt/google/** mr,
deny /selinux/ r,
deny /proc/*/task/ r,
deny /proc/ r,
deny /proc/*/cmdline r,
audit deny /home/*/.mozilla/plugins/ r,
audit deny /tmp/** rlk,
audit deny /proc/filesystems r,
/etc/pulse/client.conf r,
/etc/udev/udev.conf r,
/etc/xdg/Trolltech.conf rk,
/etc/xdg/sni-qt.conf rk,
owner /home/*/.ICEauthority r,
owner /home/*/.Xauthority r,
owner /home/*/.cache/dconf/user rw,
owner /home/*/.cache/spotify/ r,
owner /home/*/.cache/spotify/** rwk,
owner /home/*/.config/Trolltech.conf rk,
owner /home/*/.config/dconf/user r,
owner /home/*/.config/spotify/** rwk,
owner /home/*/.config/user-dirs.dirs r,
owner /home/*/.fontconfig/* r,
owner /home/*/.fonts/* r,
owner /home/*/.local/share/mime/mime.cache r,
owner /home/*/.local/share/spotify/* w,
owner /home/*/.pki/nssdb/* rwk,
owner /home/*/.pulse-cookie rwk,
owner /home/*/.config/ibus/bus/ w,
owner /proc/*/oom_score_adj w,
owner /proc/*/auxv r,
owner /proc/*/fd/ r,
owner /proc/*/maps r,
owner /proc/*/stat r,
owner /proc/*/status r,
/proc/meminfo r,
/proc/stat r,
/proc/sys/kernel/pid_max r,
/proc/sys/kernel/shmmax r,
/proc/tty/drivers r,
/proc/uptime r,
/proc/version r,
/run/shm/ r,
/run/shm/* rwk,
/sys/bus/pci/devices/ r,
/sys/devices/** r,
/tmp/** w,
/usr/bin/setarch rix,
/usr/bin/tr rix,
/usr/lib/nspluginwrapper/i386/linux/npviewer rix,
/usr/lib/nspluginwrapper/i386/linux/npviewer.bin rix,
/usr/lib{,32,64}/** mr,
/usr/share/glib-2.0/** r,
/usr/share/misc/pci.ids r,
/usr/share/themes/** r,
/var/lib/dbus/* r,
}