Code:
# Last Modified: Sun Jun 14 05:30:44 2009
#include <tunables/global>
/usr/lib/firefox-3.0.11/firefox.sh {
#include <abstractions/audio>
#include <abstractions/base>
#include <abstractions/bash>
#include <abstractions/consoles>
#include <abstractions/dbus>
#include <abstractions/fonts>
#include <abstractions/gnome>
#include <abstractions/kde>
#include <abstractions/nameservice>
#include <abstractions/nvidia>
#include <abstractions/user-tmp>
capability sys_ptrace,
deny /etc/fstab r,
deny /home/*/.bash* rw,
deny /home/*/.gnupg/* rw,
deny /home/*/.ssh/* rw,
/bin/dash rix,
/bin/grep rix,
/bin/ls mrix,
/bin/ps rix,
/bin/sed rix,
/bin/uname rix,
/bin/which rix,
/dev/ r,
/dev/shm/ r,
owner /dev/shm/* rw,
/dev/zero mrw,
/etc/ r,
/etc/X11/cursors/* r,
/etc/default/apport r,
/etc/firefox-3.0/pref/ r,
/etc/firefox-3.0/pref/** r,
/etc/gre.d/ r,
/etc/gre.d/** r,
/etc/java-6-openjdk/** r,
/etc/kde4/kdeglobals r,
/etc/kde4rc r,
/etc/lsb-release r,
/etc/mailcap r,
/etc/mime.types r,
/etc/mplayer/* r,
/etc/openoffice/soffice.sh r,
/etc/pulse/client.conf r,
/etc/sound/events/gtk-events-2.soundlist r,
/etc/ssl/certs/java/cacerts r,
/etc/xulrunner-1.9/* r,
owner /home/*/ r,
owner /home/*/.cache/ rwk,
owner /home/*/.cache/gnome-mplayer/plugin/ rw,
owner /home/*/.cache/gnome-mplayer/plugin/** rw,
owner /home/*/.config/Trolltech.conf rk,
owner /home/*/.config/gtk-2.0/ rw,
owner /home/*/.config/qtcurve.gtk-icons rw,
owner /home/*/.config/transmission/lock rwk,
owner /home/*/.gnome2/ rw,
owner /home/*/.gnome2/accels/ rw,
owner /home/*/.gnome2_private/ rw,
owner /home/*/.icedteaplugin/* rw,
owner /home/*/.kde/share/apps/kpdf/ rw,
owner /home/*/.kde/share/apps/okular/ rw,
owner /home/*/.kde/share/apps/okular/** rw,
owner /home/*/.kde/share/config/ w,
owner /home/*/.kde/share/config/* rw,
owner /home/*/.kde/share/config/kdeglobals k,
owner /home/*/.kde/share/icons/KDE4CrystalDiamondIcons_1.1_Kubuntu/** rw,
owner /home/*/.macromedia/Flash_Player/** rw,
owner /home/*/.mozilla/firefox/** rwk,
owner /home/*/.netx/ rw,
owner /home/*/.pulse-cookie rwk,
owner /home/*/.pulse/ rw,
owner /home/*/.recently-used.xbel* rwk,
/home/*/.selected_editor r,
owner /home/*/Desktop/* rw,
owner /home/*/Download/** rw,
owner /home/*/Pictures/** rw,
owner /home/.mozilla/{firefox*,plugins,extensions}/ rw,
owner /home/.mozilla/{firefox*,plugins,extensions}/** mrwk,
owner /home/*/** r,
owner /home/*/.config/Trolltech.conf rwk,
/proc/ r,
/proc/*/cmdline r,
owner /proc/*/fd/ r,
owner /proc/*/mounts r,
/proc/*/net/if_inet6 r,
/proc/*/net/ipv6_route r,
/proc/*/stat r,
/proc/*/status r,
/proc/cpuinfo r,
/proc/meminfo r,
/proc/sys/kernel/pid_max r,
/proc/tty/drivers r,
/proc/uptime r,
/proc/version r,
/sys/devices/system/cpu/ r,
/usr/bin/basename rix,
/usr/bin/dcop rix,
/usr/bin/dirname rix,
/usr/bin/env rix,
/usr/bin/gconftool-2 rix,
/usr/bin/gnome-mplayer rix,
/usr/bin/kde4-config rix,
/usr/bin/mencoder rix,
/usr/bin/mplayer rix,
/usr/bin/okular rix,
/usr/bin/ps2pdf rix,
/usr/bin/setarch rix,
/usr/bin/soffice r,
/usr/bin/stat rix,
/usr/bin/transmission rix,
/usr/lib/firefox-3.0.11/firefox rix,
/usr/lib/jvm/java-6-openjdk/jre/bin/java rix,
/usr/lib/kde4/libexec/drkonqi rix,
/usr/lib/nspluginwrapper/i386/linux/npviewer* rix,
/usr/lib/openoffice/* r,
/usr/lib/openoffice/** rix,
/usr/lib/ure/bin/javaldx rix,
/usr/lib{,32,64}/** mr,
/usr/share/ghostscript/8.64/Resource/Init/gs_init.ps r,
/usr/share/java/* r,
/usr/share/javazi/ r,
/usr/share/javazi/** r,
/usr/share/kde4/* r,
/usr/share/kde4/** r,
/usr/share/kubuntu-default-settings/kde4-profile/default/share/** r,
/usr/share/libthai/* r,
/usr/share/myspell/** r,
/usr/share/zoneinfo/ r,
/var/lib/flashplugin-installer/npwrapper.libflashplayer.so mr,
}
Bookmarks