diff --git a/apparmor.d/groups/apps/discord b/apparmor.d/groups/apps/discord index 99ea2b8ab..67a9fc366 100644 --- a/apparmor.d/groups/apps/discord +++ b/apparmor.d/groups/apps/discord @@ -29,6 +29,8 @@ profile discord @{exec_path} { include include + # userns, + signal (send) set=(kill, term) peer=@{profile_name}//lsb_release, # Needed for Game Activity diff --git a/apparmor.d/groups/kde/plasmashell b/apparmor.d/groups/kde/plasmashell index fc25e2b56..2c96258a5 100644 --- a/apparmor.d/groups/kde/plasmashell +++ b/apparmor.d/groups/kde/plasmashell @@ -25,6 +25,8 @@ profile plasmashell @{exec_path} flags=(mediate_deleted) { include include + # userns, + network inet dgram, network inet6 dgram, network inet stream, diff --git a/apparmor.d/groups/systemd/systemd-coredump b/apparmor.d/groups/systemd/systemd-coredump index 774654af0..b283e9cc0 100644 --- a/apparmor.d/groups/systemd/systemd-coredump +++ b/apparmor.d/groups/systemd/systemd-coredump @@ -14,6 +14,8 @@ profile systemd-coredump @{exec_path} flags=(attach_disconnected,mediate_deleted include include + # userns, + capability dac_override, capability dac_read_search, capability net_admin, diff --git a/apparmor.d/profiles-a-f/element-desktop b/apparmor.d/profiles-a-f/element-desktop index affdd2d3d..89b290fb7 100644 --- a/apparmor.d/profiles-a-f/element-desktop +++ b/apparmor.d/profiles-a-f/element-desktop @@ -18,6 +18,8 @@ profile element-desktop @{exec_path} { include include + # userns, + capability sys_ptrace, network inet dgram, diff --git a/apparmor.d/profiles-a-f/flatpak b/apparmor.d/profiles-a-f/flatpak index 853f665f0..4e1039137 100644 --- a/apparmor.d/profiles-a-f/flatpak +++ b/apparmor.d/profiles-a-f/flatpak @@ -17,7 +17,8 @@ profile flatpak @{exec_path} flags=(attach_disconnected,mediate_deleted,complain include include include - include + + # userns, capability dac_override, capability dac_read_search, diff --git a/apparmor.d/profiles-s-z/steam b/apparmor.d/profiles-s-z/steam index 055e894b5..cae6799d9 100644 --- a/apparmor.d/profiles-s-z/steam +++ b/apparmor.d/profiles-s-z/steam @@ -20,6 +20,8 @@ profile steam @{exec_path} flags=(attach_disconnected,mediate_deleted,complain) include include + # userns, + capability sys_ptrace, network inet dgram,