feat(profiles): ensure gpg stays confined.

This commit is contained in:
Alexandre Pujol 2023-03-12 15:33:21 +00:00
parent 3349dbda7f
commit 25e2d9d1f4
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
4 changed files with 4 additions and 4 deletions

View file

@ -15,7 +15,7 @@ profile browserpass @{exec_path} flags=(attach_disconnected) {
@{exec_path} mr,
/{usr/,}bin/gpg{,2} rUx,
/{usr/,}bin/gpg{,2} rPx,
owner @{HOME}/.password-store/{,**} r,
owner @{HOME}/.mozilla/firefox/[0-9a-z]*.*/.parentlock rw,