diff options
author | Julien Morvan <julien.morvan@outlook.com> | 2015-07-28 14:56:33 +0000 |
---|---|---|
committer | Julien Morvan <julien.morvan@outlook.com> | 2015-07-28 14:56:33 +0000 |
commit | 8f898484dc5034bb8900ee989c88ed31787ca442 (patch) | |
tree | af6db17c2484b385f19e426ba17ed3b7ed1490c2 /contrib/apparmor | |
parent | 42762fe40aaaf40bec4c20b821f074e082397351 (diff) | |
download | gnunet-8f898484dc5034bb8900ee989c88ed31787ca442.tar.gz gnunet-8f898484dc5034bb8900ee989c88ed31787ca442.zip |
Add AppArmor profiles
Diffstat (limited to 'contrib/apparmor')
52 files changed, 1328 insertions, 0 deletions
diff --git a/contrib/apparmor/usr.local.bin.gnunet-arm b/contrib/apparmor/usr.local.bin.gnunet-arm new file mode 100644 index 000000000..83f758238 --- /dev/null +++ b/contrib/apparmor/usr.local.bin.gnunet-arm | |||
@@ -0,0 +1,27 @@ | |||
1 | #/usr/local/lib Last Modified: Fri Jul 3 14:48:33 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/bin/gnunet-arm { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/local/bin/gnunet-arm mr, | ||
8 | |||
9 | /usr/lib/gconv/gconv-modules r, | ||
10 | |||
11 | /usr/local/lib/libgnunetarm.so.* mr, | ||
12 | |||
13 | /dev/null ra, | ||
14 | |||
15 | /usr/lib/locale/locale-archive r, | ||
16 | |||
17 | /usr/share/locale/locale.alias r, | ||
18 | /usr/share/locale/fr/LC_MESSAGES/libc.mo r, | ||
19 | |||
20 | #Gnunet service | ||
21 | /usr/local/lib/gnunet/libexec/gnunet-service-arm Px , | ||
22 | |||
23 | /tmp/gnunet-*-runtime/ rw, | ||
24 | /tmp/gnunet-*-runtime/gnunet-service-arm.sock rw, | ||
25 | |||
26 | #/tmp/gnunet-gnunet-runtime/* rw, | ||
27 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-exit b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-exit new file mode 100644 index 000000000..122b729bd --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-exit | |||
@@ -0,0 +1,23 @@ | |||
1 | # Last Modified: Mon Jul 27 15:57:50 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-daemon-exit { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/lib/ld-*.so r, | ||
8 | |||
9 | /usr/lib/locale/locale-archive r, | ||
10 | |||
11 | /usr/local/lib/gnunet/libexec/gnunet-daemon-exit mr, | ||
12 | |||
13 | #Gnunet librairies | ||
14 | /usr/local/lib/libgnunetcadet.so.* mr, | ||
15 | /usr/local/lib/libgnunetdht.so.* mr, | ||
16 | /usr/local/lib/libgnunetdnsstub.so.* mr, | ||
17 | /usr/local/lib/libgnunetregex.so.* mr, | ||
18 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
19 | /usr/local/lib/libgnunettun.so.* mr, | ||
20 | |||
21 | /usr/share/locale/locale.alias r, | ||
22 | |||
23 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-hostlist b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-hostlist new file mode 100644 index 000000000..d9d32cb61 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-hostlist | |||
@@ -0,0 +1,65 @@ | |||
1 | # Last Modified: Fri Jul 10 10:43:55 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-daemon-hostlist { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /etc/gai.conf r, | ||
8 | /etc/host.conf r, | ||
9 | /etc/hosts r, | ||
10 | /etc/nsswitch.conf r, | ||
11 | /etc/resolv.conf r, | ||
12 | |||
13 | /usr/lib/gconv/gconv-modules r, | ||
14 | |||
15 | #Librairies | ||
16 | /usr/lib/ld-*.so r, | ||
17 | /usr/lib/libacl.so.* mr, | ||
18 | /usr/lib/libattr.so.* mr, | ||
19 | /usr/lib/libcap.so.* mr, | ||
20 | /usr/lib/libcom_err.so.* mr, | ||
21 | /usr/lib/libcrypto.so.* mr, | ||
22 | /usr/lib/libffi.so.* mr, | ||
23 | /usr/lib/libgmp.so.* mr, | ||
24 | /usr/lib/libgnurl.so.* mr, | ||
25 | /usr/lib/libgnutls.so.* mr, | ||
26 | /usr/lib/libgssapi_krb5.so.* mr, | ||
27 | /usr/lib/libhogweed.so.* mr, | ||
28 | /usr/lib/libidn.so.* mr, | ||
29 | /usr/lib/libk5crypto.so.* mr, | ||
30 | /usr/lib/libkeyutils.so.* mr, | ||
31 | /usr/lib/libkrb5.so.* mr, | ||
32 | /usr/lib/libkrb5support.so.* mr, | ||
33 | /usr/lib/liblz4.so.* mr, | ||
34 | /usr/lib/liblzma.so.* mr, | ||
35 | /usr/lib/libmicrohttpd.so.* mr, | ||
36 | /usr/lib/libnettle.so.* mr, | ||
37 | /usr/lib/libnss_dns-*.so mr, | ||
38 | /usr/lib/libnss_files-*.so mr, | ||
39 | /usr/lib/libnss_gns.so.* mr, | ||
40 | /usr/lib/libnss_myhostname.so.* mr, | ||
41 | /usr/lib/libp11-kit.so.* mr, | ||
42 | /usr/lib/libpthread-*.so mr, | ||
43 | /usr/lib/libresolv-*.so mr, | ||
44 | /usr/lib/librt-*.so mr, | ||
45 | /usr/lib/libseccomp.so.* mr, | ||
46 | /usr/lib/libssh2.so.* mr, | ||
47 | /usr/lib/libssl.so.* mr, | ||
48 | /usr/lib/libtasn1.so.* mr, | ||
49 | |||
50 | /usr/lib/locale/locale-archive r, | ||
51 | |||
52 | /usr/local/lib/gnunet/libexec/gnunet-daemon-hostlist mr, | ||
53 | |||
54 | #Gnunet librairies | ||
55 | /usr/local/lib/libgnunetats.so.* mr, | ||
56 | /usr/local/lib/libgnunetcore.so.* mr, | ||
57 | /usr/local/lib/libgnunethello.so.* mr, | ||
58 | /usr/local/lib/libgnunetpeerinfo.so.* mr, | ||
59 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
60 | /usr/local/lib/libgnunettransport.so.* mr, | ||
61 | /usr/local/lib/libgnunetutil.so.* mr, | ||
62 | |||
63 | /usr/share/locale/fr/LC_MESSAGES/libc.mo r, | ||
64 | /usr/share/locale/locale.alias r, | ||
65 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-latency-logger b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-latency-logger new file mode 100644 index 000000000..a25852bf8 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-latency-logger | |||
@@ -0,0 +1,16 @@ | |||
1 | # Last Modified: Mon Jul 27 16:25:08 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-daemon-latency-logger { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/lib/ld-*.so r, | ||
8 | /usr/lib/libpthread-*.so mr, | ||
9 | /usr/lib/libsqlite3.so.* mr, | ||
10 | /usr/lib/locale/locale-archive r, | ||
11 | /usr/local/lib/gnunet/libexec/gnunet-daemon-latency-logger mr, | ||
12 | /usr/local/lib/libgnunetats.so.* mr, | ||
13 | /usr/local/lib/libgnunethello.so.* mr, | ||
14 | /usr/share/locale/locale.alias r, | ||
15 | |||
16 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-pt b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-pt new file mode 100644 index 000000000..95a1bcf52 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-pt | |||
@@ -0,0 +1,25 @@ | |||
1 | # Last Modified: Mon Jul 20 17:48:20 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-daemon-pt { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | #Librairies | ||
8 | /usr/lib/ld-*.so r, | ||
9 | /usr/lib/libidn.so.* mr, | ||
10 | |||
11 | /usr/lib/locale/locale-archive r, | ||
12 | |||
13 | /usr/local/lib/gnunet/libexec/gnunet-daemon-pt mr, | ||
14 | |||
15 | #Gnunet librairies | ||
16 | /usr/local/lib/libgnunetcadet.so.* mr, | ||
17 | /usr/local/lib/libgnunetdht.so.* mr, | ||
18 | /usr/local/lib/libgnunetdns.so.* mr, | ||
19 | /usr/local/lib/libgnunetdnsparser.so.* mr, | ||
20 | /usr/local/lib/libgnunetmesh.so.* mr, | ||
21 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
22 | /usr/local/lib/libgnunetvpn.so.* mr, | ||
23 | |||
24 | /usr/share/locale/locale.alias r, | ||
25 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-regexprofiler b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-regexprofiler new file mode 100644 index 000000000..da3d40887 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-regexprofiler | |||
@@ -0,0 +1,12 @@ | |||
1 | # Last Modified: Tue Jul 28 11:42:58 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-daemon-regexprofiler flags=(complain) { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/local/lib/gnunet/libexec/gnunet-daemon-regexprofiler mr, | ||
8 | /usr/local/lib/libgnunetdht.so.* mr, | ||
9 | /usr/local/lib/libgnunetregexblock.so.* mr, | ||
10 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
11 | |||
12 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-testbed-blacklist b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-testbed-blacklist new file mode 100644 index 000000000..15fa9ffe5 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-testbed-blacklist | |||
@@ -0,0 +1,12 @@ | |||
1 | # Last Modified: Tue Jul 28 11:42:58 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-daemon-testbed-blacklist flags=(complain) { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/local/lib/gnunet/libexec/gnunet-daemon-testbed-blacklist mr, | ||
8 | /usr/local/lib/libgnunetats.so.* mr, | ||
9 | /usr/local/lib/libgnunethello.so.* mr, | ||
10 | /usr/local/lib/libgnunettransport.so.* mr, | ||
11 | |||
12 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-testbed-underlay b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-testbed-underlay new file mode 100644 index 000000000..260b60400 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-testbed-underlay | |||
@@ -0,0 +1,22 @@ | |||
1 | # Last Modified: Mon Jul 27 16:37:03 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-daemon-testbed-underlay { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | #Librairies | ||
8 | /usr/lib/ld-*.so r, | ||
9 | /usr/lib/libpthread-*.so mr, | ||
10 | /usr/lib/libsqlite3.so.* mr, | ||
11 | |||
12 | /usr/lib/locale/locale-archive r, | ||
13 | |||
14 | /usr/local/lib/gnunet/libexec/gnunet-daemon-testbed-underlay mr, | ||
15 | |||
16 | #Gnunet librairies | ||
17 | /usr/local/lib/libgnunetats.so.* mr, | ||
18 | /usr/local/lib/libgnunethello.so.* mr, | ||
19 | /usr/local/lib/libgnunettransport.so.* mr, | ||
20 | |||
21 | /usr/share/locale/locale.alias r, | ||
22 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-topology b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-topology new file mode 100644 index 000000000..eb1d9306f --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-daemon-topology | |||
@@ -0,0 +1,26 @@ | |||
1 | # Last Modified: Fri Jul 3 17:37:12 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-daemon-topology { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/local/lib/gnunet/libexec/gnunet-daemon-topology mr, | ||
8 | |||
9 | #Gnunet librairies | ||
10 | /usr/local/lib/libgnunetats.so.* mr, | ||
11 | /usr/local/lib/libgnunetfriends.so.* mr, | ||
12 | /usr/local/lib/libgnunetcore.so.* mr, | ||
13 | /usr/local/lib/libgnunetpeerinfo.so.* mr, | ||
14 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
15 | /usr/local/lib/libgnunettransport.so.* mr, | ||
16 | /usr/local/lib/libgnunethello.so.* mr, | ||
17 | |||
18 | /usr/lib/ld-*.so r, | ||
19 | |||
20 | /usr/lib//locale/locale-archive r, | ||
21 | |||
22 | /usr/lib/gconv/gconv-modules r, | ||
23 | |||
24 | /usr/share/locale/locale.alias r, | ||
25 | /usr/share/locale/fr/LC_MESSAGES/libc.mo r, | ||
26 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-dns2gns b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-dns2gns new file mode 100644 index 000000000..5b1bdc2b0 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-dns2gns | |||
@@ -0,0 +1,25 @@ | |||
1 | # Last Modified: Tue Jul 21 16:45:05 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-dns2gns { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | #Librairies | ||
8 | /usr/lib/ld-*.so r, | ||
9 | /usr/lib/libidn.so.* mr, | ||
10 | |||
11 | /usr/lib/locale/locale-archive r, | ||
12 | |||
13 | /usr/local/lib/gnunet/libexec/gnunet-dns2gns mr, | ||
14 | |||
15 | #Gnunet librairies | ||
16 | /usr/local/lib/libgnunetdnsparser.so.* mr, | ||
17 | /usr/local/lib/libgnunetdnsstub.so.* mr, | ||
18 | /usr/local/lib/libgnunetgns.so.* mr, | ||
19 | /usr/local/lib/libgnunetgnsrecord.so.* mr, | ||
20 | /usr/local/lib/libgnunetidentity.so.* mr, | ||
21 | /usr/local/lib/libgnunetnamestore.so.* mr, | ||
22 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
23 | |||
24 | /usr/share/locale/locale.alias r, | ||
25 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-gns-proxy b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-gns-proxy new file mode 100644 index 000000000..62efa7744 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-gns-proxy | |||
@@ -0,0 +1,49 @@ | |||
1 | # Last Modified: Tue Jul 21 16:35:07 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-gns-proxy { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /etc/ssl/openssl.cnf r, | ||
8 | |||
9 | @{HOME}/.local/share/gnunet/gns/gns_ca_cert.pem r, | ||
10 | |||
11 | #Librairies | ||
12 | /usr/lib/gconv/gconv-modules r, | ||
13 | /usr/lib/ld-*.so r, | ||
14 | /usr/lib/libcom_err.so.* mr, | ||
15 | /usr/lib/libcrypto.so.* mr, | ||
16 | /usr/lib/libffi.so.* mr, | ||
17 | /usr/lib/libgmp.so.* mr, | ||
18 | /usr/lib/libgnurl.so.* mr, | ||
19 | /usr/lib/libgnutls.so.* mr, | ||
20 | /usr/lib/libgssapi_krb5.so.* mr, | ||
21 | /usr/lib/libhogweed.so.* mr, | ||
22 | /usr/lib/libidn.so.* mr, | ||
23 | /usr/lib/libk5crypto.so.* mr, | ||
24 | /usr/lib/libkeyutils.so.* mr, | ||
25 | /usr/lib/libkrb5.so.* mr, | ||
26 | /usr/lib/libkrb5support.so.* mr, | ||
27 | /usr/lib/libltdl.so.* mr, | ||
28 | /usr/lib/libmicrohttpd.so.* mr, | ||
29 | /usr/lib/libnettle.so.* mr, | ||
30 | /usr/lib/libp11-kit.so.* mr, | ||
31 | /usr/lib/libpthread-*.so mr, | ||
32 | /usr/lib/libresolv-*.so mr, | ||
33 | /usr/lib/libssh2.so.* mr, | ||
34 | /usr/lib/libssl.so.* mr, | ||
35 | /usr/lib/libtasn1.so.* mr, | ||
36 | |||
37 | /usr/lib/locale/locale-archive r, | ||
38 | |||
39 | /usr/local/lib/gnunet/libexec/gnunet-gns-proxy mr, | ||
40 | |||
41 | #Gnunet librairies | ||
42 | /usr/local/lib/libgnunetdnsparser.so.* mr, | ||
43 | /usr/local/lib/libgnunetgns.so.* mr, | ||
44 | /usr/local/lib/libgnunetgnsrecord.so.* mr, | ||
45 | /usr/local/lib/libgnunetidentity.so.* mr, | ||
46 | |||
47 | /usr/share/locale/fr/LC_MESSAGES/libc.mo r, | ||
48 | /usr/share/locale/locale.alias r, | ||
49 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-audio-playback b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-audio-playback new file mode 100644 index 000000000..b6663899e --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-audio-playback | |||
@@ -0,0 +1,9 @@ | |||
1 | # Last Modified: Tue Jul 28 11:46:24 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-helper-audio-playback flags=(complain) { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | #include <abstractions/gnunet-libaudio> | ||
7 | |||
8 | /usr/local/lib/gnunet/libexec/gnunet-helper-audio-playback mr, | ||
9 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-audio-record b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-audio-record new file mode 100644 index 000000000..e0a41edc3 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-audio-record | |||
@@ -0,0 +1,9 @@ | |||
1 | # Last Modified: Tue Jul 28 11:42:58 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-helper-audio-record flags=(complain) { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | #include <abstractions/gnunet-libaudio> | ||
7 | |||
8 | /usr/local/lib/gnunet/libexec/gnunet-helper-audio-record mr, | ||
9 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-dns b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-dns new file mode 100644 index 000000000..960cf09b5 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-dns | |||
@@ -0,0 +1,43 @@ | |||
1 | # Last Modified: Mon Jul 27 15:24:34 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-helper-dns flags=(complain) { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | capability net_admin, | ||
8 | capability net_raw, | ||
9 | capability setuid, | ||
10 | |||
11 | /dev/net/tun rw, | ||
12 | /dev/null rw, | ||
13 | |||
14 | /etc/gai.conf r, | ||
15 | /etc/group r, | ||
16 | /etc/iproute2/rt_tables r, | ||
17 | /etc/nsswitch.conf r, | ||
18 | /etc/protocols r, | ||
19 | |||
20 | @{PROC}/@{pid}/net/ip_tables_names r, | ||
21 | @{PROC}/sys/net/ipv4/conf/all/rp_filter rw, | ||
22 | @{PROC}/sys/net/ipv4/conf/default/rp_filter rw, | ||
23 | |||
24 | /usr/bin/ip rix, | ||
25 | /usr/bin/sysctl rix, | ||
26 | /usr/bin/xtables-multi rix, | ||
27 | |||
28 | /usr/lib/iptables/libxt_MARK.so mr, | ||
29 | /usr/lib/iptables/libxt_owner.so mr, | ||
30 | /usr/lib/iptables/libxt_standard.so mr, | ||
31 | /usr/lib/iptables/libxt_udp.so mr, | ||
32 | |||
33 | /usr/lib/ld-*.so r, | ||
34 | /usr/lib/libip4tc.so.* mr, | ||
35 | /usr/lib/libip6tc.so.* mr, | ||
36 | /usr/lib/libnss_files-*.so mr, | ||
37 | |||
38 | /usr/lib/libxtables.so.* mr, | ||
39 | |||
40 | /usr/lib/locale/locale-archive r, | ||
41 | |||
42 | /usr/local/lib/gnunet/libexec/gnunet-helper-dns mr, | ||
43 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-exit b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-exit new file mode 100644 index 000000000..e18b49358 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-exit | |||
@@ -0,0 +1,11 @@ | |||
1 | # Last Modified: Tue Jul 28 11:44:00 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-helper-exit flags=(complain) { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | capability setuid, | ||
8 | |||
9 | /usr/local/lib/gnunet/libexec/gnunet-helper-exit mr, | ||
10 | |||
11 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-fs-publish b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-fs-publish new file mode 100644 index 000000000..ad0a142f7 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-fs-publish | |||
@@ -0,0 +1,13 @@ | |||
1 | # Last Modified: Tue Jul 28 11:42:58 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-helper-fs-publish flags=(complain) { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/lib/libbz2.so.* mr, | ||
8 | /usr/lib/libextractor.so.* mr, | ||
9 | /usr/lib/libpthread-*.so mr, | ||
10 | /usr/lib/librt-*.so mr, | ||
11 | |||
12 | /usr/local/lib/gnunet/libexec/gnunet-helper-fs-publish mr, | ||
13 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-nat-client b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-nat-client new file mode 100644 index 000000000..32cb42552 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-nat-client | |||
@@ -0,0 +1,11 @@ | |||
1 | # Last Modified: Tue Jul 28 11:44:00 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-helper-nat-client flags=(complain) { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | capability setuid, | ||
8 | |||
9 | /usr/local/lib/gnunet/libexec/gnunet-helper-nat-client mr, | ||
10 | |||
11 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-nat-server b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-nat-server new file mode 100644 index 000000000..c3bd37910 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-nat-server | |||
@@ -0,0 +1,11 @@ | |||
1 | # Last Modified: Tue Jul 28 11:44:00 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-helper-nat-server flags=(complain) { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | capability setuid, | ||
8 | |||
9 | /usr/local/lib/gnunet/libexec/gnunet-helper-nat-server mr, | ||
10 | |||
11 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-testbed b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-testbed new file mode 100644 index 000000000..8c6748d4a --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-testbed | |||
@@ -0,0 +1,36 @@ | |||
1 | # Last Modified: Mon Jul 27 11:02:37 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-helper-testbed flags=(complain) { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /dev/null rw, | ||
8 | |||
9 | /etc/gai.conf r, | ||
10 | |||
11 | /usr/lib/ld-*.so r, | ||
12 | |||
13 | /usr/lib/locale/locale-archive r, | ||
14 | |||
15 | /usr/share/locale/locale.alias r, | ||
16 | /usr/share/locale/fr/LC_MESSAGES/libc.mo r, | ||
17 | |||
18 | /usr/lib/gconv/gconv-modules r, | ||
19 | |||
20 | /usr/local/lib/gnunet/libexec/ r, | ||
21 | /usr/local/lib/gnunet/libexec/gnunet-helper-testbed mr, | ||
22 | /usr/local/lib/gnunet/libexec/gnunet-service-arm r, | ||
23 | /usr/local/lib/gnunet/libexec/gnunet-service-testbed Px, | ||
24 | |||
25 | #Gnunet librairies | ||
26 | /usr/local/lib/libgnunetarm.so.* mr, | ||
27 | /usr/local/lib/libgnunetats.so.* mr, | ||
28 | /usr/local/lib/libgnunetcore.so.* mr, | ||
29 | /usr/local/lib/libgnunethello.so.* mr, | ||
30 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
31 | /usr/local/lib/libgnunettestbed.so.* mr, | ||
32 | /usr/local/lib/libgnunettesting.so.* mr, | ||
33 | /usr/local/lib/libgnunettransport.so.* mr, | ||
34 | |||
35 | /usr/local/share/gnunet/testing_hostkeys.ecc r, | ||
36 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-transport-wlan b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-transport-wlan new file mode 100644 index 000000000..6f2f98e15 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-transport-wlan | |||
@@ -0,0 +1,11 @@ | |||
1 | # Last Modified: Tue Jul 28 11:44:00 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-helper-transport-wlan flags=(complain) { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | capability setuid, | ||
8 | |||
9 | /usr/local/lib/gnunet/libexec/gnunet-helper-transport-wlan mr, | ||
10 | |||
11 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-transport-wlan-dummy b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-transport-wlan-dummy new file mode 100644 index 000000000..d9ffed813 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-transport-wlan-dummy | |||
@@ -0,0 +1,9 @@ | |||
1 | # Last Modified: Tue Jul 28 11:36:52 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-helper-transport-wlan-dummy flags=(complain) { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/local/lib/gnunet/libexec/gnunet-helper-transport-wlan-dummy mr, | ||
8 | |||
9 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-vpn b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-vpn new file mode 100644 index 000000000..3f9051db3 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-vpn | |||
@@ -0,0 +1,16 @@ | |||
1 | # Last Modified: Mon Jul 27 11:06:22 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-helper-vpn flags=(complain) { | ||
5 | |||
6 | capability net_admin, | ||
7 | capability setuid, | ||
8 | |||
9 | /dev/net/tun rw, | ||
10 | /etc/ld.so.cache r, | ||
11 | /usr/lib/ld-*.so r, | ||
12 | /usr/lib/libc-*.so mr, | ||
13 | /usr/lib/libm-*.so mr, | ||
14 | /usr/local/lib/gnunet/libexec/gnunet-helper-vpn mr, | ||
15 | |||
16 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-namestore-fcfsd b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-namestore-fcfsd new file mode 100644 index 000000000..43527ae3b --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-namestore-fcfsd | |||
@@ -0,0 +1,30 @@ | |||
1 | # Last Modified: Tue Jul 21 17:25:12 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-namestore-fcfsd { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | #Librairies | ||
8 | /usr/lib/ld-*.so r, | ||
9 | /usr/lib/libffi.so.* mr, | ||
10 | /usr/lib/libgmp.so.* mr, | ||
11 | /usr/lib/libgnutls.so.* mr, | ||
12 | /usr/lib/libhogweed.so.* mr, | ||
13 | /usr/lib/libidn.so.* mr, | ||
14 | /usr/lib/libmicrohttpd.so.* mr, | ||
15 | /usr/lib/libnettle.so.* mr, | ||
16 | /usr/lib/libp11-kit.so.* mr, | ||
17 | /usr/lib/libpthread-*.so mr, | ||
18 | /usr/lib/libtasn1.so.* mr, | ||
19 | |||
20 | /usr/lib/locale/locale-archive r, | ||
21 | |||
22 | /usr/local/lib/gnunet/libexec/gnunet-namestore-fcfsd mr, | ||
23 | |||
24 | #Gnunet librairies | ||
25 | /usr/local/lib/libgnunetdnsparser.so.* mr, | ||
26 | /usr/local/lib/libgnunetgnsrecord.so.* mr, | ||
27 | /usr/local/lib/libgnunetidentity.so.* mr, | ||
28 | /usr/local/lib/libgnunetnamestore.so.* mr, | ||
29 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
30 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-arm b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-arm new file mode 100644 index 000000000..fe3f037ed --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-arm | |||
@@ -0,0 +1,109 @@ | |||
1 | # Last Modified: Thu Jul 9 10:27:23 2015 | ||
2 | |||
3 | #include <tunables/global> | ||
4 | |||
5 | /usr/local/lib/gnunet/libexec/gnunet-service-arm { | ||
6 | #include <abstractions/gnunet-common> | ||
7 | |||
8 | /dev/null ra, | ||
9 | |||
10 | /tmp/gnunet-*-runtime/ rw, | ||
11 | /tmp/gnunet-*-runtime/gnunet-service-arm.sock rw, | ||
12 | /tmp/gnunet-*-runtime/gnunet-service-gns.sock rw, | ||
13 | /tmp/gnunet-*-runtime/gnunet-service-identity.unix rw, | ||
14 | /tmp/gnunet-*-runtime/gnunet-service-namestore.sock rw, | ||
15 | |||
16 | /tmp/gnunet-system-runtime/ rw, | ||
17 | /tmp/gnunet-system-runtime/gnunet-service-*.sock rw, | ||
18 | /tmp/gnunet-system-runtime/gnunet-service-nse.unix rw, | ||
19 | /tmp/gnunet-system-runtime/gnunet-service-revocation.unix rw, | ||
20 | |||
21 | /var/lib/gnunet/.local/share/gnunet/ r, | ||
22 | /var/lib/gnunet/.local/share/gnunet/revocation.dat r, | ||
23 | /var/lib/gnunet/.local/share/gnunet/peerstore/ a, | ||
24 | /var/lib/gnunet/.local/share/gnunet/peerstore/sqlite.db rwk, | ||
25 | /var/lib/gnunet/.local/share/gnunet/peerstore/sqlite.db-journal rw, | ||
26 | /var/lib/gnunet/.config/gnunet.conf r, | ||
27 | |||
28 | #Librairies | ||
29 | /usr/lib/ld-*.so r, | ||
30 | /usr/lib/libpthread-*.so mr, | ||
31 | |||
32 | /usr/lib/libsqlite3.so.* mr, | ||
33 | |||
34 | /usr/lib/locale/locale-archive r, | ||
35 | |||
36 | /usr/share/locale/locale-alias r, | ||
37 | |||
38 | /usr/local/lib/gnunet/libexec/gnunet-service-arm mr, | ||
39 | |||
40 | /usr/local/lib/gnunet/ r, | ||
41 | |||
42 | /usr/local/lib/gnunet/libexec/ r, | ||
43 | |||
44 | #Gnunet daemon | ||
45 | /usr/local/lib/gnunet/libexec/gnunet-daemon-exit Px, | ||
46 | /usr/local/lib/gnunet/libexec/gnunet-daemon-hostlist Px, | ||
47 | /usr/local/lib/gnunet/libexec/gnunet-daemon-latency-logger Px, | ||
48 | /usr/local/lib/gnunet/libexec/gnunet-daemon-testbed-underlay Px, | ||
49 | /usr/local/lib/gnunet/libexec/gnunet-daemon-topology Px, | ||
50 | /usr/local/lib/gnunet/libexec/gnunet-daemon-pt Px, | ||
51 | |||
52 | /usr/local/lib/gnunet/libexec/gnunet-dns2gns Px, | ||
53 | |||
54 | /usr/local/lib/gnunet/libexec/gnunet-gns-proxy Px, | ||
55 | |||
56 | /usr/local/lib/gnunet/libexec/gnunet-namestore-fcfsd Px, | ||
57 | |||
58 | #Gnunet service | ||
59 | /usr/local/lib/gnunet/libexec/gnunet-service-ats Px, | ||
60 | /usr/local/lib/gnunet/libexec/gnunet-service-cadet Px, | ||
61 | /usr/local/lib/gnunet/libexec/gnunet-service-core Px, | ||
62 | /usr/local/lib/gnunet/libexec/gnunet-service-conversation Px, | ||
63 | /usr/local/lib/gnunet/libexec/gnunet-service-datastore Px, | ||
64 | /usr/local/lib/gnunet/libexec/gnunet-service-dht Px, | ||
65 | /usr/local/lib/gnunet/libexec/gnunet-service-dns Px, | ||
66 | /usr/local/lib/gnunet/libexec/gnunet-service-fs Px, | ||
67 | /usr/local/lib/gnunet/libexec/gnunet-service-gns Px, | ||
68 | /usr/local/lib/gnunet/libexec/gnunet-service-identity Px, | ||
69 | /usr/local/lib/gnunet/libexec/gnunet-service-mesh Px, | ||
70 | /usr/local/lib/gnunet/libexec/gnunet-service-namecache Px, | ||
71 | /usr/local/lib/gnunet/libexec/gnunet-service-namestore Px, | ||
72 | /usr/local/lib/gnunet/libexec/gnunet-service-nse Px, | ||
73 | /usr/local/lib/gnunet/libexec/gnunet-service-peerinfo Px, | ||
74 | /usr/local/lib/gnunet/libexec/gnunet-service-peerstore Px, | ||
75 | /usr/local/lib/gnunet/libexec/gnunet-service-regex Px, | ||
76 | /usr/local/lib/gnunet/libexec/gnunet-service-resolver Px, | ||
77 | /usr/local/lib/gnunet/libexec/gnunet-service-revocation Px, | ||
78 | /usr/local/lib/gnunet/libexec/gnunet-service-set Px, | ||
79 | /usr/local/lib/gnunet/libexec/gnunet-service-scalarproduct-alice Px, | ||
80 | /usr/local/lib/gnunet/libexec/gnunet-service-scalarproduct-bob Px, | ||
81 | /usr/local/lib/gnunet/libexec/gnunet-service-statistics Px, | ||
82 | /usr/local/lib/gnunet/libexec/gnunet-service-template Px, | ||
83 | /usr/local/lib/gnunet/libexec/gnunet-service-testbed Px, | ||
84 | /usr/local/lib/gnunet/libexec/gnunet-service-testbed-logger Px, | ||
85 | /usr/local/lib/gnunet/libexec/gnunet-service-transport Px, | ||
86 | /usr/local/lib/gnunet/libexec/gnunet-service-vpn Px, | ||
87 | |||
88 | #Gnunet helper | ||
89 | /usr/local/lib/gnunet/libexec/gnunet-helper-dns r, | ||
90 | |||
91 | #Gnunet librairies | ||
92 | /usr/local/lib/libgnunetats.so.* mr, | ||
93 | /usr/local/lib/libgnunetcadet.so.* mr, | ||
94 | /usr/local/lib/libgnunetdht.so.* mr, | ||
95 | /usr/local/lib/libgnunetdnsstub.so.* mr, | ||
96 | /usr/local/lib/libgnunetgnsrecord.so.* r, | ||
97 | /usr/local/lib/libgnunethello.so.* mr, | ||
98 | /usr/local/lib/libgnunetnamecache.so.* r, | ||
99 | /usr/local/lib/libgnunetpeerstore.so.* mr, | ||
100 | /usr/local/lib/libgnunetregex.so.* mr, | ||
101 | /usr/local/lib/libgnunetset.so.* mr, | ||
102 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
103 | /usr/local/lib/libgnunettransport.so.* mr, | ||
104 | /usr/local/lib/libgnunettun.so.* mr, | ||
105 | |||
106 | #Gnunet plugin | ||
107 | /usr/local/lib/gnunet/libgnunet_plugin_peerstore_sqlite.la r, | ||
108 | /usr/local/lib/gnunet/libgnunet_plugin_peerstore_sqlite.so mr, | ||
109 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-ats b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-ats new file mode 100644 index 000000000..86273dc34 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-ats | |||
@@ -0,0 +1,19 @@ | |||
1 | # Last Modified: Wed Jul 8 10:49:34 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-ats { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/local/lib/gnunet/libexec/gnunet-service-ats mr, | ||
8 | |||
9 | #Gnunet librairies | ||
10 | /usr/local/lib/libgnunethello.so.* mr, | ||
11 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
12 | /usr/local/lib/libgnunetats.so.* mr, | ||
13 | |||
14 | #Gnunet plugin | ||
15 | /usr/local/lib/gnunet/libgnunet_plugin_ats_proportional.la r, | ||
16 | /usr/local/lib/gnunet/libgnunet_plugin_ats_proportional.so mr, | ||
17 | |||
18 | /usr/lib/ld-*.so r, | ||
19 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-cadet b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-cadet new file mode 100644 index 000000000..f834a6d05 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-cadet | |||
@@ -0,0 +1,21 @@ | |||
1 | # Last Modified: Mon Jul 27 11:09:34 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-cadet { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/lib/ld-*.so r, | ||
8 | /usr/lib/libpthread-*.so mr, | ||
9 | /usr/lib/librt-*.so mr, | ||
10 | /usr/local/lib/gnunet/libexec/gnunet-service-cadet mr, | ||
11 | /usr/local/lib/libgnunetats.so.* mr, | ||
12 | /usr/local/lib/libgnunetblock.so.* mr, | ||
13 | /usr/local/lib/libgnunetcore.so.* mr, | ||
14 | /usr/local/lib/libgnunetdht.so.* mr, | ||
15 | /usr/local/lib/libgnunethello.so.* mr, | ||
16 | /usr/local/lib/libgnunetpeerinfo.so.* mr, | ||
17 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
18 | /usr/local/lib/libgnunettransport.so.* mr, | ||
19 | /var/lib/gnunet/.local/share/gnunet/private_key.ecc rk, | ||
20 | |||
21 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-conversation b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-conversation new file mode 100644 index 000000000..9b952866e --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-conversation | |||
@@ -0,0 +1,27 @@ | |||
1 | # Last Modified: Tue Jul 21 16:53:39 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-conversation { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | #Librairies | ||
8 | /usr/lib/ld-*.so r, | ||
9 | /usr/lib/libidn.so.* mr, | ||
10 | |||
11 | /usr/local/lib/gnunet/libexec/gnunet-service-conversation mr, | ||
12 | |||
13 | #Gnunet librairies | ||
14 | /usr/local/lib/libgnunetcadet.so.* mr, | ||
15 | /usr/local/lib/libgnunetconversation.so.* mr, | ||
16 | /usr/local/lib/libgnunetdnsparser.so.* mr, | ||
17 | /usr/local/lib/libgnunetgns.so.* mr, | ||
18 | /usr/local/lib/libgnunetgnsrecord.so.* mr, | ||
19 | /usr/local/lib/libgnunetidentity.so.* mr, | ||
20 | /usr/local/lib/libgnunetmesh.so.* mr, | ||
21 | /usr/local/lib/libgnunetmicrophone.so.* mr, | ||
22 | /usr/local/lib/libgnunetnamestore.so.* mr, | ||
23 | /usr/local/lib/libgnunetspeaker.so.* mr, | ||
24 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
25 | |||
26 | /var/lib/gnunet/.local/share/gnunet/private_key.ecc rk, | ||
27 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-core b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-core new file mode 100644 index 000000000..e2b4229bb --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-core | |||
@@ -0,0 +1,19 @@ | |||
1 | # Last Modified: Thu Jul 9 10:16:30 2015 | ||
2 | |||
3 | #include <tunables/global> | ||
4 | |||
5 | /usr/local/lib/gnunet/libexec/gnunet-service-core { | ||
6 | #include <abstractions/gnunet-common> | ||
7 | |||
8 | /var/lib/gnunet/.local/share/gnunet/private_key.ecc rk, | ||
9 | |||
10 | /usr/lib/ld-*.so r, | ||
11 | |||
12 | /usr/local/lib/gnunet/libexec/gnunet-service-core mr, | ||
13 | |||
14 | #Gnunet librairies | ||
15 | /usr/local/lib/libgnunetats.so.* mr, | ||
16 | /usr/local/lib/libgnunethello.so.* mr, | ||
17 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
18 | /usr/local/lib/libgnunettransport.so.* mr, | ||
19 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-datastore b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-datastore new file mode 100644 index 000000000..b38121e65 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-datastore | |||
@@ -0,0 +1,26 @@ | |||
1 | # Last Modified: Thu Jul 9 10:16:30 2015 | ||
2 | |||
3 | #include <tunables/global> | ||
4 | |||
5 | /usr/local/lib/gnunet/libexec/gnunet-service-datastore { | ||
6 | #include <abstractions/gnunet-common> | ||
7 | |||
8 | /var/lib/gnunet/.local/share/gnunet/datastore/bloomfilter.sqlite rw, | ||
9 | /var/lib/gnunet/.local/share/gnunet/datastore/sqlite.db rwk, | ||
10 | /var/lib/gnunet/.local/share/gnunet/datastore/sqlite.db-journal rw, | ||
11 | |||
12 | #Librairies | ||
13 | /usr/lib/ld-*.so r, | ||
14 | /usr/lib/libpthread-*.so mr, | ||
15 | /usr/lib/libsqlite3.so.* mr, | ||
16 | |||
17 | /usr/local/lib/gnunet/libexec/gnunet-service-datastore mr, | ||
18 | |||
19 | #Gnunet plugin | ||
20 | /usr/local/lib/gnunet/libgnunet_plugin_datastore_sqlite.la r, | ||
21 | /usr/local/lib/gnunet/libgnunet_plugin_datastore_sqlite.so mr, | ||
22 | |||
23 | #Gnunet Librairies | ||
24 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
25 | /usr/local/lib/libgnunetutil.so.* mr, | ||
26 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-dht b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-dht new file mode 100644 index 000000000..224465cd5 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-dht | |||
@@ -0,0 +1,56 @@ | |||
1 | # Last Modified: Fri Jul 3 17:37:39 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-dht { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/local/lib/gnunet/libexec/gnunet-service-dht mr, | ||
8 | |||
9 | #Gnunet librairies | ||
10 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
11 | /usr/local/lib/libgnunetcore.so.* mr, | ||
12 | /usr/local/lib/libgnunetnse.so.* mr, | ||
13 | /usr/local/lib/libgnunetats.so.* mr, | ||
14 | /usr/local/lib/libgnunettransport.so.* mr, | ||
15 | /usr/local/lib/libgnunetpeerinfo.so.* mr, | ||
16 | /usr/local/lib/libgnunethello.so.* mr, | ||
17 | /usr/local/lib/libgnunetblock.so.* mr, | ||
18 | /usr/local/lib/libgnunetdatacache.so.* mr, | ||
19 | /usr/local/lib/libgnunetfs.so.* mr, | ||
20 | /usr/local/lib/libgnunetdatastore.so.* mr, | ||
21 | /usr/local/lib/libgnunetregexblock.so.* mr, | ||
22 | /usr/local/lib/libgnunetgnsrecord.so.* mr, | ||
23 | /usr/local/lib/libgnunetdnsparser.so.* mr, | ||
24 | |||
25 | #Gnunet plugin | ||
26 | /usr/local/lib/gnunet/ r, | ||
27 | /usr/local/lib/gnunet/libgnunet_plugin_block_template.la r, | ||
28 | /usr/local/lib/gnunet/libgnunet_plugin_block_template.so mr, | ||
29 | /usr/local/lib/gnunet/libgnunet_plugin_block_dns.la r, | ||
30 | /usr/local/lib/gnunet/libgnunet_plugin_block_dns.so mr, | ||
31 | /usr/local/lib/gnunet/libgnunet_plugin_block_fs.la r, | ||
32 | /usr/local/lib/gnunet/libgnunet_plugin_block_fs.so mr, | ||
33 | /usr/local/lib/gnunet/libgnunet_plugin_block_regex.la r, | ||
34 | /usr/local/lib/gnunet/libgnunet_plugin_block_regex.so mr, | ||
35 | /usr/local/lib/gnunet/libgnunet_plugin_block_dht.la r, | ||
36 | /usr/local/lib/gnunet/libgnunet_plugin_block_dht.so mr, | ||
37 | /usr/local/lib/gnunet/libgnunet_plugin_block_dht.so mr, | ||
38 | /usr/local/lib/gnunet/libgnunet_plugin_block_test.la r, | ||
39 | /usr/local/lib/gnunet/libgnunet_plugin_block_test.so mr, | ||
40 | /usr/local/lib/gnunet/libgnunet_plugin_block_gns.la r, | ||
41 | /usr/local/lib/gnunet/libgnunet_plugin_block_gns.so mr, | ||
42 | /usr/local/lib/gnunet/libgnunet_plugin_datacache_heap.la r, | ||
43 | /usr/local/lib/gnunet/libgnunet_plugin_datacache_heap.so mr, | ||
44 | |||
45 | #Librairies | ||
46 | /usr/lib/ld-*.so r, | ||
47 | /usr/lib/libextractor.so.* mr, | ||
48 | /usr/lib/libbz2.so.* mr, | ||
49 | /usr/lib/librt-*.so mr, | ||
50 | /usr/lib/libpthread-*.so mr, | ||
51 | /usr/lib/libidn.so.* mr, | ||
52 | |||
53 | /tmp/gnunet-system-runtime/gnunet-service-dht.sock w, | ||
54 | |||
55 | /tmp/gnunet-datacachebloom* rw, | ||
56 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-dns b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-dns new file mode 100644 index 000000000..2f2dd711a --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-dns | |||
@@ -0,0 +1,19 @@ | |||
1 | # Last Modified: Mon Jul 27 15:18:30 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-dns { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | capability setgid, | ||
8 | |||
9 | /usr/lib/ld-*.so r, | ||
10 | |||
11 | /usr/local/lib/gnunet/libexec/gnunet-helper-dns Px, | ||
12 | |||
13 | /usr/local/lib/gnunet/libexec/gnunet-service-dns mr, | ||
14 | |||
15 | #Gnunet librairies | ||
16 | /usr/local/lib/libgnunetdnsstub.so.* mr, | ||
17 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
18 | /usr/local/lib/libgnunettun.so.* mr, | ||
19 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-fs b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-fs new file mode 100644 index 000000000..247d29282 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-fs | |||
@@ -0,0 +1,59 @@ | |||
1 | # Last Modified: Wed Jul 8 10:52:48 2015 | ||
2 | |||
3 | #include <tunables/global> | ||
4 | |||
5 | /usr/local/lib/gnunet/libexec/gnunet-service-fs { | ||
6 | #include <abstractions/gnunet-common> | ||
7 | |||
8 | /etc/gnunet.conf r, | ||
9 | @{HOME}/.config/gnunet.conf r, | ||
10 | |||
11 | /tmp/gnunet-system-runtime/gnunet-service-fs.sock w, | ||
12 | |||
13 | /var/lib/gnunet/.local/share/gnunet/private_key.ecc rk, | ||
14 | |||
15 | owner @{HOME}/.local/share/gnunet/fs/idxinfo.lst r, | ||
16 | |||
17 | #Librairies | ||
18 | /usr/lib/ld-*.so r, | ||
19 | /usr/lib/libbz2.so.* mr, | ||
20 | /usr/lib/libextractor.so.* mr, | ||
21 | /usr/lib/libidn.so.* mr, | ||
22 | /usr/lib/libpthread-*.so mr, | ||
23 | /usr/lib/librt-*.so mr, | ||
24 | |||
25 | /usr/local/lib/gnunet/libexec/gnunet-service-fs mr, | ||
26 | |||
27 | #Gnunet plugin | ||
28 | /usr/local/lib/gnunet/ r, | ||
29 | /usr/local/lib/gnunet/libgnunet_plugin_block_dht.la r, | ||
30 | /usr/local/lib/gnunet/libgnunet_plugin_block_dht.so mr, | ||
31 | /usr/local/lib/gnunet/libgnunet_plugin_block_dns.la r, | ||
32 | /usr/local/lib/gnunet/libgnunet_plugin_block_dns.so mr, | ||
33 | /usr/local/lib/gnunet/libgnunet_plugin_block_fs.la r, | ||
34 | /usr/local/lib/gnunet/libgnunet_plugin_block_fs.so mr, | ||
35 | /usr/local/lib/gnunet/libgnunet_plugin_block_gns.la r, | ||
36 | /usr/local/lib/gnunet/libgnunet_plugin_block_gns.so mr, | ||
37 | /usr/local/lib/gnunet/libgnunet_plugin_block_regex.la r, | ||
38 | /usr/local/lib/gnunet/libgnunet_plugin_block_regex.so mr, | ||
39 | /usr/local/lib/gnunet/libgnunet_plugin_block_template.la r, | ||
40 | /usr/local/lib/gnunet/libgnunet_plugin_block_template.so mr, | ||
41 | /usr/local/lib/gnunet/libgnunet_plugin_block_test.la r, | ||
42 | /usr/local/lib/gnunet/libgnunet_plugin_block_test.so mr, | ||
43 | |||
44 | #Gnunet librairies | ||
45 | /usr/local/lib/libgnunetats.so.* mr, | ||
46 | /usr/local/lib/libgnunetblock.so.* mr, | ||
47 | /usr/local/lib/libgnunetcadet.so.* mr, | ||
48 | /usr/local/lib/libgnunetcore.so.* mr, | ||
49 | /usr/local/lib/libgnunetdatastore.so.* mr, | ||
50 | /usr/local/lib/libgnunetdht.so.* mr, | ||
51 | /usr/local/lib/libgnunetdnsparser.so.* mr, | ||
52 | /usr/local/lib/libgnunetfs.so.* mr, | ||
53 | /usr/local/lib/libgnunetgnsrecord.so.* mr, | ||
54 | /usr/local/lib/libgnunethello.so.* mr, | ||
55 | /usr/local/lib/libgnunetmesh.so.* mr, | ||
56 | /usr/local/lib/libgnunetpeerstore.so.* mr, | ||
57 | /usr/local/lib/libgnunetregexblock.so.* mr, | ||
58 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
59 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-gns b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-gns new file mode 100644 index 000000000..c7f650d1b --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-gns | |||
@@ -0,0 +1,29 @@ | |||
1 | # Last Modified: Wed Jul 8 15:17:46 2015 | ||
2 | |||
3 | #include <tunables/global> | ||
4 | |||
5 | /usr/local/lib/gnunet/libexec/gnunet-service-gns { | ||
6 | #include <abstractions/gnunet-common> | ||
7 | |||
8 | @{HOME}/.config/gnunet.conf r, | ||
9 | |||
10 | #Librairies | ||
11 | /usr/lib/ld-2.21.so r, | ||
12 | /usr/lib/libidn.so.* mr, | ||
13 | |||
14 | /usr/local/lib/gnunet/libexec/gnunet-service-gns mr, | ||
15 | |||
16 | #Gnunet librairies | ||
17 | /usr/local/lib/libgnunetdht.so.* mr, | ||
18 | /usr/local/lib/libgnunetdns.so.* mr, | ||
19 | /usr/local/lib/libgnunetdnsparser.so.* mr, | ||
20 | /usr/local/lib/libgnunetdnsstub.so.* mr, | ||
21 | /usr/local/lib/libgnunetgnsrecord.so.* mr, | ||
22 | /usr/local/lib/libgnunetidentity.so.* mr, | ||
23 | /usr/local/lib/libgnunetnamecache.so.* mr, | ||
24 | /usr/local/lib/libgnunetnamestore.so.* mr, | ||
25 | /usr/local/lib/libgnunetrevocation.so.* mr, | ||
26 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
27 | /usr/local/lib/libgnunettun.so.* mr, | ||
28 | /usr/local/lib/libgnunetvpn.so.* mr, | ||
29 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-identity b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-identity new file mode 100644 index 000000000..7e550acb9 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-identity | |||
@@ -0,0 +1,24 @@ | |||
1 | # Last Modified: Tue Jul 21 11:51:29 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-identity { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /tmp/gnunet-*-runtime/ a, | ||
8 | |||
9 | /usr/lib/ld-*.so r, | ||
10 | |||
11 | /var/lib/gnunet/.local/share/gnunet/identity/ a, | ||
12 | /var/lib/gnunet/.local/share/gnunet/identity/egos/ ra, | ||
13 | |||
14 | /usr/local/lib/gnunet/libexec/gnunet-service-identity mr, | ||
15 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
16 | |||
17 | @{HOME}/.config/gnunet/identity/subsystem_defaults.conf rw, | ||
18 | |||
19 | @{HOME}/.local/share/gnunet/identity/egos/ r, | ||
20 | @{HOME}/.local/share/gnunet/identity/egos/master-zone rk, | ||
21 | @{HOME}/.local/share/gnunet/identity/egos/private-zone rk, | ||
22 | @{HOME}/.local/share/gnunet/identity/egos/short-zone rk, | ||
23 | @{HOME}/.local/share/gnunet/identity/egos/sks-zone rk, | ||
24 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-mesh b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-mesh new file mode 100644 index 000000000..1496e228f --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-mesh | |||
@@ -0,0 +1,29 @@ | |||
1 | # Last Modified: Fri Jul 3 17:37:56 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-mesh { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/local/lib/gnunet/libexec/gnunet-service-mesh mr, | ||
8 | |||
9 | #Gnunet librairies | ||
10 | /usr/local/lib/libgnunetats.so.* mr, | ||
11 | /usr/local/lib/libgnunettransport.so.* mr, | ||
12 | /usr/local/lib/libgnunetcore.so.* mr, | ||
13 | /usr/local/lib/libgnunetdht.so.* mr, | ||
14 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
15 | /usr/local/lib/libgnunetpeerinfo.so.* mr, | ||
16 | /usr/local/lib/libgnunethello.so.* mr, | ||
17 | /usr/local/lib/libgnunetblock.so.* mr, | ||
18 | |||
19 | #Librairies | ||
20 | /usr/lib/librt-*.so mr, | ||
21 | /usr/lib/libpthread-*.so mr, | ||
22 | /usr/lib/ld-*.so r, | ||
23 | |||
24 | @{HOME}/.local/share/gnunet/private_key.ecc rk, | ||
25 | |||
26 | /tmp/gnunet-system-runtime/gnunet-service-mesh.sock w, | ||
27 | |||
28 | /var/lib/gnunet/.local/share/gnunet/private_key.ecc rwk, | ||
29 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-namecache b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-namecache new file mode 100644 index 000000000..6338c9a5b --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-namecache | |||
@@ -0,0 +1,29 @@ | |||
1 | # Last Modified: Thu Jul 9 10:01:49 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-namecache { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/local/lib/gnunet/libexec/gnunet-service-namecache mr, | ||
8 | |||
9 | #Gnunet librairies | ||
10 | /usr/local/lib/libgnunetdnsparser.so.* mr, | ||
11 | /usr/local/lib/libgnunetnamecache.so.* mr, | ||
12 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
13 | /usr/local/lib/libgnunetgnsrecord.so.* mr, | ||
14 | |||
15 | #Gnunet plugin | ||
16 | /usr/local/lib/gnunet/libgnunet_plugin_namecache_sqlite.la r, | ||
17 | /usr/local/lib/gnunet/libgnunet_plugin_namecache_sqlite.so mr, | ||
18 | |||
19 | /var/lib/gnunet/.local/share/gnunet/namecache/ r, | ||
20 | /var/lib/gnunet/.local/share/gnunet/namecache/sqlite.db rwk, | ||
21 | /var/lib/gnunet/.local/share/gnunet/namecache/sqlite.db-journal rw, | ||
22 | |||
23 | #Librairies | ||
24 | /usr/lib/libpthread-*.so mr, | ||
25 | /usr/lib/libsqlite3.so.* mr, | ||
26 | /usr/lib/libidn.so.* mr, | ||
27 | /usr/lib/ld-*.so r, | ||
28 | } | ||
29 | |||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-namestore b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-namestore new file mode 100644 index 000000000..3b917a2a3 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-namestore | |||
@@ -0,0 +1,35 @@ | |||
1 | # Last Modified: Tue Jul 7 10:43:41 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-namestore { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/local/lib/gnunet/libexec/gnunet-service-namestore mr, | ||
8 | |||
9 | #Gnunet librairies | ||
10 | /usr/local/lib/libgnunetnamecache.so.* mr, | ||
11 | /usr/local/lib/libgnunetgnsrecord.so.* mr, | ||
12 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
13 | /usr/local/lib/libgnunetnamestore.so.* mr, | ||
14 | /usr/local/lib/libgnunetdnsparser.so.* mr, | ||
15 | |||
16 | #Gnunet plugin | ||
17 | /usr/local/lib/gnunet/libgnunet_plugin_namestore_sqlite.la r, | ||
18 | /usr/local/lib/gnunet/libgnunet_plugin_namestore_sqlite.so mr, | ||
19 | |||
20 | #Librairies | ||
21 | /usr/lib/libidn.so.* mr, | ||
22 | /usr/lib/ld-*.so r, | ||
23 | /usr/lib/libsqlite3.so.* mr, | ||
24 | /usr/lib/libpthread-*.so mr, | ||
25 | |||
26 | /var/lib/gnunet/.local/share/gnunet/namestore/ ra, | ||
27 | /var/lib/gnunet/.local/share/gnunet/namestore/sqlite.db rwk, | ||
28 | /var/lib/gnunet/.local/share/gnunet/namestore/sqlite.db-journal rw, | ||
29 | |||
30 | @{HOME}/.local/share/gnunet/namestore/ r, | ||
31 | @{HOME}/.local/share/gnunet/namestore/sqlite.db rwk, | ||
32 | @{HOME}/.local/share/gnunet/namestore/sqlite.db-journal rw, | ||
33 | |||
34 | /tmp/gnunet-*-runtime/ a, | ||
35 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-nse b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-nse new file mode 100644 index 000000000..54acd5215 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-nse | |||
@@ -0,0 +1,23 @@ | |||
1 | # Last Modified: Fri Jul 3 17:37:49 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-nse { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/local/lib/gnunet/libexec/gnunet-service-nse mr, | ||
8 | |||
9 | #Gnunet librairies | ||
10 | /usr/local/lib/libgnunetnse.so.* mr, | ||
11 | /usr/local/lib/libgnunetcore.so.* mr, | ||
12 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
13 | |||
14 | /usr/lib/ld-*.so mr, | ||
15 | |||
16 | /tmp/gnunet-system-runtime/gnunet-service-nse.unix w, | ||
17 | |||
18 | @{HOME}/.local/share/gnunet/private_key.ecc rk, | ||
19 | owner @{HOME}/.local/share/gnunet/nse/proof.dat rw, | ||
20 | |||
21 | /var/lib/gnunet/.local/share/gnunet/private_key.ecc rwk, | ||
22 | /var/lib/gnunet/.local/share/gnunet/nse/proof.dat rw, | ||
23 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-peerinfo b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-peerinfo new file mode 100644 index 000000000..8c7f079b4 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-peerinfo | |||
@@ -0,0 +1,20 @@ | |||
1 | # Last Modified: Wed Jul 8 17:03:17 2015 | ||
2 | |||
3 | #include <tunables/global> | ||
4 | |||
5 | /usr/local/lib/gnunet/libexec/gnunet-service-peerinfo { | ||
6 | #include <abstractions/gnunet-common> | ||
7 | |||
8 | /usr/local/share/gnunet/hellos/ r, | ||
9 | /usr/local/share/gnunet/hellos/* r, | ||
10 | |||
11 | /var/lib/gnunet/.local/share/gnunet/peerinfo/hosts/ r, | ||
12 | /var/lib/gnunet/.local/share/gnunet/peerinfo/hosts/* rw, | ||
13 | |||
14 | /usr/lib/ld-*.so r, | ||
15 | |||
16 | /usr/local/lib/gnunet/libexec/gnunet-service-peerinfo mr, | ||
17 | |||
18 | /usr/local/lib/libgnunethello.so.* mr, | ||
19 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
20 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-peerstore b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-peerstore new file mode 100644 index 000000000..0f9f8ed8c --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-peerstore | |||
@@ -0,0 +1,23 @@ | |||
1 | # Last Modified: Mon Jul 27 11:06:13 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-peerstore { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | #Librairies | ||
8 | /usr/lib/ld-*.so r, | ||
9 | /usr/lib/libpthread-*.so mr, | ||
10 | /usr/lib/libsqlite3.so.* mr, | ||
11 | |||
12 | /usr/local/lib/gnunet/libexec/gnunet-service-peerstore mr, | ||
13 | |||
14 | #Gnunet Plugin | ||
15 | /usr/local/lib/gnunet/libgnunet_plugin_peerstore_sqlite.la r, | ||
16 | /usr/local/lib/gnunet/libgnunet_plugin_peerstore_sqlite.so mr, | ||
17 | |||
18 | #Gnunet librairies | ||
19 | /usr/local/lib/libgnunetpeerstore.so.* mr, | ||
20 | |||
21 | /var/lib/gnunet/.local/share/gnunet/peerstore/sqlite.db rwk, | ||
22 | /var/lib/gnunet/.local/share/gnunet/peerstore/sqlite.db-journal rw, | ||
23 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-regex b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-regex new file mode 100644 index 000000000..e82f0483a --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-regex | |||
@@ -0,0 +1,17 @@ | |||
1 | # Last Modified: Tue Jul 21 16:59:39 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-regex { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/lib/ld-*.so r, | ||
8 | |||
9 | /usr/local/lib/gnunet/libexec/gnunet-service-regex mr, | ||
10 | |||
11 | #Gnunet librairies | ||
12 | /usr/local/lib/libgnunetdht.so.* mr, | ||
13 | /usr/local/lib/libgnunetregexblock.so.* mr, | ||
14 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
15 | |||
16 | /var/lib/gnunet/.local/share/gnunet/private_key.ecc rk, | ||
17 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-resolver b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-resolver new file mode 100644 index 000000000..0ffa5cea2 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-resolver | |||
@@ -0,0 +1,32 @@ | |||
1 | # Last Modified: Thu Jul 9 10:01:36 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-resolver { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/local/lib/gnunet/libexec/gnunet-service-resolver mr, | ||
8 | |||
9 | #Librairies | ||
10 | /usr/lib/ld-*.so r, | ||
11 | /usr/lib/libnss_files-*.so mr, | ||
12 | /usr/lib/libnss_gns.so.* mr, | ||
13 | /usr/lib/libnss_dns-*.so mr, | ||
14 | /usr/lib/libresolv-*.so mr, | ||
15 | /usr/lib/libnss_myhostname.so.* mr, | ||
16 | /usr/lib/librt-*.so mr, | ||
17 | /usr/lib/liblzma.so.* mr, | ||
18 | /usr/lib/liblz4.so.* mr, | ||
19 | /usr/lib/libacl.so.* mr, | ||
20 | /usr/lib/libidn.so.* mr, | ||
21 | /usr/lib/libseccomp.so.* mr, | ||
22 | /usr/lib/libcap.so.* mr, | ||
23 | /usr/lib/libpthread-*.so mr, | ||
24 | /usr/lib/libattr.so.* mr, | ||
25 | |||
26 | /etc/nsswitch.conf r, | ||
27 | /etc/resolv.conf r, | ||
28 | /etc/host.conf r, | ||
29 | /etc/hosts r, | ||
30 | |||
31 | /tmp/gnunet-system-runtime/gnunet-service-resolver.sock w, | ||
32 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-revocation b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-revocation new file mode 100644 index 000000000..c226502b3 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-revocation | |||
@@ -0,0 +1,26 @@ | |||
1 | # Last Modified: Thu Jul 9 10:16:30 2015 | ||
2 | |||
3 | #include <tunables/global> | ||
4 | |||
5 | /usr/local/lib/gnunet/libexec/gnunet-service-revocation { | ||
6 | #include <abstractions/gnunet-common> | ||
7 | |||
8 | /etc/gnunet.conf r, | ||
9 | @{HOME}/.config/gnunet.conf r, | ||
10 | |||
11 | /tmp/gnunet-system-runtime/gnunet-service-revocation.unix w, | ||
12 | |||
13 | /var/lib/gnunet/.local/share/gnunet/revocation.dat rw, | ||
14 | |||
15 | @{HOME}/.local/share/gnunet/revocation.dat rw, | ||
16 | |||
17 | /usr/lib/ld-*.so r, | ||
18 | |||
19 | /usr/local/lib/gnunet/libexec/gnunet-service-revocation mr, | ||
20 | |||
21 | #Gnunet librairies | ||
22 | /usr/local/lib/libgnunetcore.so.* mr, | ||
23 | /usr/local/lib/libgnunetrevocation.so.* mr, | ||
24 | /usr/local/lib/libgnunetset.so.* mr, | ||
25 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
26 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-scalarproduct-alice b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-scalarproduct-alice new file mode 100644 index 000000000..e61a20daa --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-scalarproduct-alice | |||
@@ -0,0 +1,12 @@ | |||
1 | # Last Modified: Mon Jul 27 15:48:05 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-scalarproduct-alice { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/lib/ld-*.so r, | ||
8 | /usr/local/lib/gnunet/libexec/gnunet-service-scalarproduct-alice mr, | ||
9 | /usr/local/lib/libgnunetcadet.so.* mr, | ||
10 | /usr/local/lib/libgnunetset.so.* mr, | ||
11 | |||
12 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-scalarproduct-bob b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-scalarproduct-bob new file mode 100644 index 000000000..c48ac50dc --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-scalarproduct-bob | |||
@@ -0,0 +1,11 @@ | |||
1 | # Last Modified: Mon Jul 27 15:48:05 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-scalarproduct-bob { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/lib/ld-*.so r, | ||
8 | /usr/local/lib/gnunet/libexec/gnunet-service-scalarproduct-bob mr, | ||
9 | /usr/local/lib/libgnunetcadet.so.* mr, | ||
10 | /usr/local/lib/libgnunetset.so.* mr, | ||
11 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-set b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-set new file mode 100644 index 000000000..d711f132c --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-set | |||
@@ -0,0 +1,17 @@ | |||
1 | # Last Modified: Wed Jul 8 10:52:48 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-set { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /usr/local/lib/gnunet/libexec/gnunet-service-set mr, | ||
8 | |||
9 | #Gnunet librairies | ||
10 | /usr/local/lib/libgnunetcadet.so.* mr, | ||
11 | /usr/local/lib/libgnunetcore.so.* mr, | ||
12 | /usr/local/lib/libgnunetmesh.so.* mr, | ||
13 | /usr/local/lib/libgnunetblock.so.* mr, | ||
14 | |||
15 | #Librairies | ||
16 | /usr/lib/ld-*.so r, | ||
17 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-statistics b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-statistics new file mode 100644 index 000000000..1ff8a8fd1 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-statistics | |||
@@ -0,0 +1,15 @@ | |||
1 | # Last Modified: Thu Jul 9 10:16:30 2015 | ||
2 | |||
3 | #include <tunables/global> | ||
4 | |||
5 | /usr/local/lib/gnunet/libexec/gnunet-service-statistics { | ||
6 | #include <abstractions/gnunet-common> | ||
7 | |||
8 | /var/lib/gnunet/.local/share/gnunet/statistics.dat rw, | ||
9 | |||
10 | /usr/lib/ld-*.so r, | ||
11 | |||
12 | /usr/local/lib/gnunet/libexec/gnunet-service-statistics mr, | ||
13 | |||
14 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
15 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-template b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-template new file mode 100644 index 000000000..15a00cbee --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-template | |||
@@ -0,0 +1,15 @@ | |||
1 | # Last Modified: Tue Jul 21 16:06:04 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-template { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /tmp/gnunet-system-runtime/ w, | ||
8 | /tmp/gnunet-system-runtime/gnunet-service-template.sock w, | ||
9 | |||
10 | #Librairies | ||
11 | /usr/lib/ld-*.so r, | ||
12 | |||
13 | #Gnunet Librairies | ||
14 | /usr/local/lib/gnunet/libexec/gnunet-service-template mr, | ||
15 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-testbed b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-testbed new file mode 100644 index 000000000..de9ad2675 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-testbed | |||
@@ -0,0 +1,35 @@ | |||
1 | # Last Modified: Mon Jul 27 11:02:46 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-testbed flags=(complain) { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | /etc/gai.conf r, | ||
8 | |||
9 | /tmp/gnunet-system-runtime/ w, | ||
10 | /tmp/gnunet-system-runtime/gnunet-service-testbed-barrier.sock w, | ||
11 | /tmp/gnunet-system-runtime/gnunet-service-testbed.sock w, | ||
12 | |||
13 | /usr/lib/ld-*.so r, | ||
14 | |||
15 | /dev/null r, | ||
16 | |||
17 | /usr/local/lib/gnunet/libexec/gnunet-* r, | ||
18 | |||
19 | /usr/local/lib/gnunet/libexec/ r, | ||
20 | /usr/local/lib/gnunet/libexec/gnunet-service-arm Px, | ||
21 | /usr/local/lib/gnunet/libexec/gnunet-service-testbed mr, | ||
22 | |||
23 | #Gnunet librairies | ||
24 | /usr/local/lib/libgnunetarm.so.* mr, | ||
25 | /usr/local/lib/libgnunetats.so.* mr, | ||
26 | /usr/local/lib/libgnunetcore.so.* mr, | ||
27 | /usr/local/lib/libgnunethello.so.* mr, | ||
28 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
29 | /usr/local/lib/libgnunettestbed.so.* mr, | ||
30 | /usr/local/lib/libgnunettesting.so.* mr, | ||
31 | /usr/local/lib/libgnunettransport.so.* mr, | ||
32 | |||
33 | /usr/local/share/gnunet/testing_hostkeys.ecc r, | ||
34 | |||
35 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-testbed-logger b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-testbed-logger new file mode 100644 index 000000000..b646b9450 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-testbed-logger | |||
@@ -0,0 +1,16 @@ | |||
1 | # Last Modified: Tue Jul 21 17:19:18 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-testbed-logger { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | #??? | ||
8 | /tmp/archlinux_*.dat w, | ||
9 | |||
10 | /tmp/gnunet-system-runtime/ w, | ||
11 | /tmp/gnunet-system-runtime/gnunet-gnunet-testbed-logger.sock w, | ||
12 | |||
13 | /usr/lib/ld-*.so r, | ||
14 | |||
15 | /usr/local/lib/gnunet/libexec/gnunet-service-testbed-logger mr, | ||
16 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-transport b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-transport new file mode 100644 index 000000000..b50541f4c --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-transport | |||
@@ -0,0 +1,28 @@ | |||
1 | # Last Modified: Thu Jul 9 10:16:30 2015 | ||
2 | |||
3 | #include <tunables/global> | ||
4 | |||
5 | /usr/local/lib/gnunet/libexec/gnunet-service-transport { | ||
6 | #include <abstractions/gnunet-common> | ||
7 | |||
8 | /var/lib/gnunet/.local/share/gnunet/private_key.ecc rk, | ||
9 | |||
10 | /usr/lib/ld-*.so r, | ||
11 | |||
12 | /usr/local/lib/gnunet/libexec/gnunet-service-transport mr, | ||
13 | |||
14 | #Gnunet plugin | ||
15 | /usr/local/lib/gnunet/libgnunet_plugin_transport_tcp.la r, | ||
16 | /usr/local/lib/gnunet/libgnunet_plugin_transport_tcp.so mr, | ||
17 | /usr/local/lib/gnunet/libgnunet_plugin_transport_udp.la r, | ||
18 | /usr/local/lib/gnunet/libgnunet_plugin_transport_udp.so mr, | ||
19 | |||
20 | #Gnunet librairies | ||
21 | /usr/local/lib/libgnunetats.so.* mr, | ||
22 | /usr/local/lib/libgnunetfragmentation.so.* mr, | ||
23 | /usr/local/lib/libgnunethello.so.* mr, | ||
24 | /usr/local/lib/libgnunetnat.so.* mr, | ||
25 | /usr/local/lib/libgnunetpeerinfo.so.* mr, | ||
26 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
27 | /usr/local/lib/libgnunettransport.so.* mr, | ||
28 | } | ||
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-vpn b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-vpn new file mode 100644 index 000000000..48fda8563 --- /dev/null +++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-service-vpn | |||
@@ -0,0 +1,26 @@ | |||
1 | # Last Modified: Mon Jul 20 11:20:57 2015 | ||
2 | #include <tunables/global> | ||
3 | |||
4 | /usr/local/lib/gnunet/libexec/gnunet-service-vpn { | ||
5 | #include <abstractions/gnunet-common> | ||
6 | |||
7 | capability setuid, | ||
8 | capability net_admin, | ||
9 | |||
10 | /dev/net/tun rw, | ||
11 | |||
12 | /usr/local/lib/gnunet/libexec/gnunet-service-vpn mr, | ||
13 | |||
14 | #Librairies | ||
15 | /usr/lib/ld-*.so r, | ||
16 | |||
17 | #Gnunet helper | ||
18 | /usr/local/lib/gnunet/libexec/gnunet-helper-vpn Px, | ||
19 | |||
20 | #Gnunet librairies | ||
21 | /usr/local/lib/libgnunetcadet.so.* mr, | ||
22 | /usr/local/lib/libgnunetmesh.so.* mr, | ||
23 | /usr/local/lib/libgnunetregex.so.* mr, | ||
24 | /usr/local/lib/libgnunetstatistics.so.* mr, | ||
25 | /usr/local/lib/libgnunettun.so.* mr, | ||
26 | } | ||