diff --git a/apparmor.d/abstractions/chromium b/apparmor.d/abstractions/chromium index ba182c7f4..fd604830c 100644 --- a/apparmor.d/abstractions/chromium +++ b/apparmor.d/abstractions/chromium @@ -25,6 +25,7 @@ include include include + include # userns, @@ -144,6 +145,18 @@ /dev/shm/ r, owner /dev/shm/.@{domain}* rw, + audit @{run}/udev/data/* r, + + @{sys}/bus/ r, + @{sys}/bus/**/devices/ r, + @{sys}/class/**/ r, + @{sys}/devices/**/uevent r, + @{sys}/devices/@{pci}/{in_intensity_sampling_frequency,in_intensity_scale,in_illuminance_raw} r, + @{sys}/devices/@{pci}/boot_vga r, + @{sys}/devices/@{pci}/report_descriptor r, + @{sys}/devices/system/cpu/kernel_max r, + @{sys}/devices/virtual/**/report_descriptor r, + @{PROC}/ r, @{PROC}/@{pid}/fd/ r, @{PROC}/@{pids}/stat r, @@ -168,27 +181,9 @@ owner @{PROC}/@{pids}/environ r, owner @{PROC}/@{pids}/task/ r, - audit @{run}/udev/data/* r, - - @{sys}/bus/ r, - @{sys}/bus/**/devices/ r, - @{sys}/class/**/ r, - @{sys}/devices/**/uevent r, - @{sys}/devices/@{pci}/{in_intensity_sampling_frequency,in_intensity_scale,in_illuminance_raw} r, - @{sys}/devices/@{pci}/boot_vga r, - @{sys}/devices/@{pci}/report_descriptor r, - @{sys}/devices/system/cpu/kernel_max r, - @{sys}/devices/virtual/**/report_descriptor r, - @{sys}/devices/virtual/dmi/id/product_name r, - @{sys}/devices/virtual/dmi/id/sys_vendor r, - @{sys}/devices/virtual/tty/tty@{int}/active r, - - /dev/ r, - /dev/hidraw@{int} rw, - /dev/tty rw, - /dev/video@{int} rw, - - # File Inherit + /dev/ r, + /dev/hidraw@{int} rw, + /dev/tty rw, owner /dev/tty@{int} rw, # Silencer