%PDF- <> %âãÏÓ endobj 2 0 obj <> endobj 3 0 obj <>/ExtGState<>/ProcSet[/PDF/Text/ImageB/ImageC/ImageI] >>/Annots[ 28 0 R 29 0 R] /MediaBox[ 0 0 595.5 842.25] /Contents 4 0 R/Group<>/Tabs/S>> endobj ºaâÚÎΞ-ÌE1ÍØÄ÷{òò2ÿ ÛÖ^ÔÀá TÎ{¦?§®¥kuµùÕ5sLOšuY>endobj 2 0 obj<>endobj 2 0 obj<>endobj 2 0 obj<>endobj 2 0 obj<> endobj 2 0 obj<>endobj 2 0 obj<>es 3 0 R>> endobj 2 0 obj<> ox[ 0.000000 0.000000 609.600000 935.600000]/Fi endobj 3 0 obj<> endobj 7 1 obj<>/ProcSet[/PDF/Text/ImageB/ImageC/ImageI]>>/Subtype/Form>> stream
# Note: This profile does not specify an attachment path because it is # intended to be used only via "Px -> lsb_release" exec transitions from # other profiles. We want to confine the lsb_release(1) utility when it # is invoked from other confined applications, but not when it is used # in regular (unconfined) shell scripts or run directly by the user. abi <abi/3.0>, include <tunables/global> # Do not attach to /usr/bin/lsb_release by default profile lsb_release { include <abstractions/base> include <abstractions/python> owner @{PROC}/@{pid}/fd/ r, /dev/tty rw, /usr/bin/lsb_release r, /usr/bin/python3.{1,}[0-9] mr, /etc/debian_version r, /etc/default/apport r, /etc/dpkg/origins/** r, /etc/lsb-release r, /etc/lsb-release.d/ r, /{usr/,}bin/bash ixr, /{usr/,}bin/dash ixr, /usr/bin/basename ixr, /usr/bin/dpkg-query ixr, /usr/bin/getopt ixr, /usr/bin/sed ixr, /usr/bin/tr ixr, # TODO - many more permissions needed for this to work deny /usr/bin/apt-cache x, /usr/bin/ r, /usr/include/python*/pyconfig.h r, /usr/share/distro-info/** r, /usr/share/dpkg/** r, /usr/share/terminfo/** r, /var/lib/dpkg/** r, # file_inherit deny /tmp/gtalkplugin.log w, # Site-specific additions and overrides. See local/README for details. include if exists <local/lsb_release> }