logo

apparmor.d

Unnamed repository; edit this file 'description' to name the repository. git clone https://hacktivis.me/git/apparmor.d.git

private-files-strict (1212B)


  1. # vim:syntax=apparmor
  2. # privacy-violations-strict contains additional rules for sensitive
  3. # files that you want to explicitly deny access
  4. abi <abi/3.0>,
  5. include <abstractions/private-files>
  6. # potentially extremely sensitive files
  7. audit deny @{HOME}/.aws/{,**} mrwkl,
  8. audit deny @{HOME}/.gnupg/{,**} mrwkl,
  9. audit deny @{HOME}/.ssh/{,**} mrwkl,
  10. audit deny @{HOME}/.gnome2_private/{,**} mrwkl,
  11. audit deny @{HOME}/.gnome2/ w,
  12. audit deny @{HOME}/.gnome2/keyrings/{,**} mrwkl,
  13. # don't allow access to any gnome-keyring modules
  14. audit deny @{run}/user/[0-9]*/keyring** mrwkl,
  15. audit deny @{HOME}/.mozilla/{,**} mrwkl,
  16. audit deny @{HOME}/.config/ w,
  17. audit deny @{HOME}/.config/chromium/{,**} mrwkl,
  18. audit deny @{HOME}/.config/evolution/{,**} mrwkl,
  19. audit deny @{HOME}/.evolution/{,**} mrwkl,
  20. audit deny @{HOME}/.{,mozilla-}thunderbird/{,**} mrwkl,
  21. audit deny @{HOME}/.kde{,4}/{,share/,share/apps/} w,
  22. audit deny @{HOME}/.kde{,4}/share/apps/kmail{,2}/{,**} mrwkl,
  23. audit deny @{HOME}/.kde{,4}/share/apps/kwallet/{,**} mrwkl,
  24. audit deny @{HOME}/.local/share/kwalletd/{,**} mrwkl,
  25. # Include additions to the abstraction
  26. include if exists <abstractions/private-files-strict.d>