diff --git a/apparmor.d/groups/apps/discord b/apparmor.d/groups/apps/discord index 8da974556..c4bb14ebe 100644 --- a/apparmor.d/groups/apps/discord +++ b/apparmor.d/groups/apps/discord @@ -29,6 +29,9 @@ profile discord @{exec_path} { @{exec_path} mrix, @{sh_path} rix, + @{lib_dirs}/chrome-sandbox rix, + @{lib_dirs}/chrome_crashpad_handler rix, + @{open_path} rPx -> child-open-browsers, /var/lib/dbus/machine-id r, @@ -38,6 +41,8 @@ profile discord @{exec_path} { owner @{tmp}/discord.sock rw, owner "@{tmp}/Discord Crashes/" rw, + owner @{config_dirs}/discord/*/modules/** rm, + owner @{run}/user/@{uid}/discord-ipc-@{int} rw, include if exists diff --git a/apparmor.d/groups/apps/discord-chrome-sandbox b/apparmor.d/groups/apps/discord-chrome-sandbox index 1c636286b..c049c03b2 100644 --- a/apparmor.d/groups/apps/discord-chrome-sandbox +++ b/apparmor.d/groups/apps/discord-chrome-sandbox @@ -16,8 +16,8 @@ include profile discord-chrome-sandbox @{exec_path} { include - capability setgid, - capability setuid, + #capability setgid, + #capability setuid, capability sys_admin, capability sys_chroot, capability sys_resource,