疑似虚拟网卡设备的MAC变动会触发记忆登录失效,以及linuxqq 其他行为,比如回去读cpuid,网卡mac,磁盘uuid,建议使用 apparmor 限制如下:
# File: /etc/apparmor.d/usr.bin.linuxqq
abi <abi/3.0>,
include <tunables/global>
/usr/bin/linuxqq {
include <abstractions/audio>
include <abstractions/base>
include <abstractions/bash>
include <abstractions/consoles>
include <abstractions/dbus-session-strict>
include <abstractions/fonts>
include <abstractions/gnome>
include <abstractions/nameservice>
include <abstractions/nvidia>
include <abstractions/ubuntu-browsers.d/user-files>
include <abstractions/vulkan>
ptrace trace peer=/usr/bin/linuxqq,
/dev/disk/by-uuid/ r,
/etc/host.conf r,
/etc/hosts r,
/etc/libva.conf r,
/etc/lsb-release r,
/etc/nsswitch.conf r,
/etc/resolv.conf r,
/opt/QQ/** mrwix,
/opt/QQ/chrome_100_percent.pak r,
/opt/QQ/chrome_200_percent.pak r,
/opt/QQ/icudtl.dat r,
/opt/QQ/libffmpeg.so mr,
/opt/QQ/locales/zh-CN.pak r,
/opt/QQ/qq mrix,
/proc/ r,
/proc/*/stat r,
/proc/devices r,
/proc/modules r,
/proc/sys/fs/inotify/max_user_watches r,
/proc/sys/kernel/yama/ptrace_scope r,
/proc/version r,
/sys/bus/pci/devices/** r,
deny /sys/class/net/** r,
deny /sys/devices/virtual/net/** r,
/sys/devices/pci0000:00/** r,
/sys/devices/system/cpu/**l r,
/sys/devices/virtual/dmi/id/bios_date r,
/sys/devices/virtual/dmi/id/bios_vendor r,
/sys/devices/virtual/dmi/id/bios_version r,
/sys/devices/virtual/dmi/id/modalias r,
/sys/devices/virtual/dmi/id/product_name r,
/sys/devices/virtual/dmi/id/sys_vendor r,
/sys/devices/virtual/tty/tty0/active r,
/usr/bin/bash ix,
/usr/bin/find ix,
/usr/bin/find r,
/usr/bin/linuxqq r,
/usr/bin/lsb_release mrix,
/usr/bin/nvidia-modprobe mrix,
/usr/lib/ r,
/usr/share/fcitx5/themes/default/theme.conf r,
/usr/share/texmf-dist/fonts/** r,
owner "/home/*/.config/QQ/Local Storage/leveldb/LOCK" k,
owner /dev/shm/** rw,
owner /home/*/ r,
owner /home/*/.Xauthority r,
owner /home/*/.cache/ rw,
owner /home/*/.cache/event-sound-cache.tdb.archlinux.x86_64-pc-linux-gnu k,
owner /home/*/.config/QQ/** rwk,
owner /home/*/.local/share/fonts/ r,
owner /home/*/.local/share/fonts/.uuid r,
owner /home/*/.pki/nssdb/cert9.db k,
owner /home/*/.pki/nssdb/key4.db k,
owner /proc/*/cmdline r,
owner /proc/*/fd/ r,
owner /proc/*/mem r,
owner /proc/*/oom_score_adj w,
owner /proc/*/statm r,
owner /proc/*/task/** r,
owner /run/user/1000/pulse/ rw,
}
Pinned Comments
Integral commented on 2023-03-14 09:20 (UTC)
目前通过删除 linuxqq 包自带的 libvips 临时解决了浏览图片时崩溃的问题 PS:感谢 @ayatale 的建议