Skip to content

Commit

Permalink
deprecate /etc/apparmor.d/home.tor-browser.start-tor-browser due to
Browse files Browse the repository at this point in the history
low attack surface and broken. Patches welcome.

fix apparmor profile matching
  • Loading branch information
Patrick Schleizer committed Nov 17, 2018
1 parent 8e76b16 commit 21c3654
Show file tree
Hide file tree
Showing 3 changed files with 7 additions and 67 deletions.
1 change: 1 addition & 0 deletions debian/apparmor-profile-torbrowser.maintscript
Original file line number Diff line number Diff line change
@@ -1,2 +1,3 @@
rm_conffile "/etc/apparmor.d/home.*.tor-browser_*.Browser.firefox"
rm_conffile "/etc/apparmor.d/home.*.tor-browser_*.Browser.start-tor-browser"
rm_conffile "/etc/apparmor.d/home.tor-browser.start-tor-browser"
12 changes: 6 additions & 6 deletions etc/apparmor.d/home.tor-browser.firefox
Original file line number Diff line number Diff line change
@@ -1,9 +1,7 @@
# Last modified: Sun May 18 19:22:08 UTC 2014
#include <tunables/global>

@{TBB} = @{HOME}*

/home/*/{tor,i2p}-browser/Browser/firefox flags=(attach_disconnected) {
/**/*-browser/Browser/firefox flags=(attach_disconnected) {
#include <abstractions/base>
#include <abstractions/fonts>
#include <abstractions/kde>
Expand Down Expand Up @@ -71,9 +69,8 @@
@{HOME}/* r,
##################################################

owner @{TBB}/{tor,i2p}-browser/** mrlwkix,
## Allow TBB installations in /home/user (not only /home/user/*/ )
owner @{HOME}/{tor,i2p}-browser/** mrlwkix,
owner /**/*-browser/** mrlwkix,

## KDE 4 ##
@{HOME}/.kde/share/config/* r,
Expand Down Expand Up @@ -101,12 +98,15 @@
/usr/bin/dirname rix,

/usr/lib/*-linux-gnu/** mrix,
/usr/lib/python3.5/lib-dynload/* mr,
/usr/lib/python*/lib-dynload/* mr,

/usr/local/share/applications/ r,
/usr/local/share/applications/meminfo.cache r,
/usr/local/share/applications/mimeinfo.cache r,

/usr/local/lib/python*/dist-packages/ r,
/usr/local/lib/python*/dist-packages/** r,

/usr/share/ r,
/usr/share/mime/ r,
/usr/share/mime/** r,
Expand Down
61 changes: 0 additions & 61 deletions etc/apparmor.d/home.tor-browser.start-tor-browser

This file was deleted.

0 comments on commit 21c3654

Please sign in to comment.