From 7e3bb8b1ea1be75c9ebd8078d788a36bf4d1e8fe Mon Sep 17 00:00:00 2001 From: nobody43 Date: Tue, 21 Feb 2023 15:24:03 +0000 Subject: [PATCH] polishing --- apparmor.d/groups/browsers/firefox | 4 ++-- apparmor.d/groups/systemd/loginctl | 4 ++-- apparmor.d/profiles-m-r/rustdesk | 2 +- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/apparmor.d/groups/browsers/firefox b/apparmor.d/groups/browsers/firefox index 8c4561375..33916fd0c 100644 --- a/apparmor.d/groups/browsers/firefox +++ b/apparmor.d/groups/browsers/firefox @@ -110,12 +110,12 @@ profile firefox @{exec_path} flags=(attach_disconnected) { dbus send bus=session path=/org/mozilla/firefox/Remote interface=org.mozilla.firefox member=OpenURL - peer=(name=org.mozilla.firefox.* label=@{profile_name}), + peer=(name=org.mozilla.firefox.*, label=@{profile_name}), dbus receive bus=session path=/org/mozilla/firefox/Remote interface=org.mozilla.firefox member=OpenURL - peer=(name=:* label=@{profile_name}), + peer=(name=:*, label=@{profile_name}), dbus bind bus=session name=org.mpris.MediaPlayer2.firefox.*, diff --git a/apparmor.d/groups/systemd/loginctl b/apparmor.d/groups/systemd/loginctl index 36564e3a7..aed5eda27 100644 --- a/apparmor.d/groups/systemd/loginctl +++ b/apparmor.d/groups/systemd/loginctl @@ -24,12 +24,12 @@ profile loginctl @{exec_path} { dbus (send) bus=system path=/org/freedesktop/login[0-9]* interface=org.freedesktop.login[0-9]*.Manager member={ListSessions,GetSession} - peer=(name=org.freedesktop.login[0-9]* label=systemd-logind), + peer=(name=org.freedesktop.login[0-9]*, label=systemd-logind), dbus (send) bus=system path=/org/freedesktop/login[0-9]*/session/** interface=org.freedesktop.DBus.Properties member={Get,GetAll} - peer=(name=org.freedesktop.login[0-9]* label=systemd-logind), + peer=(name=org.freedesktop.login[0-9]*, label=systemd-logind), include if exists } diff --git a/apparmor.d/profiles-m-r/rustdesk b/apparmor.d/profiles-m-r/rustdesk index 44e282562..69fc1077d 100644 --- a/apparmor.d/profiles-m-r/rustdesk +++ b/apparmor.d/profiles-m-r/rustdesk @@ -120,7 +120,7 @@ profile rustdesk @{exec_path} { owner @{HOME}/.xsession-errors w, # Do not reveal username (pop-up only) - deny /etc/passwd r, +# deny /etc/passwd r, # It's possible to disable root-based service ('systemctl disable rustdesk.service') and use RD only on-demand (or as client-only). After that, sudo isn't necessary. # deny /{,usr/}bin/sudo x,