# apparmor.d - Full set of apparmor profiles # Copyright (C) 2021-2024 Alexandre Pujol # Copyright (C) 2022 Jeroen Rijken # SPDX-License-Identifier: GPL-2.0-only abi , include @{bin_dirs} = @{bin}/ /snap/{snapd,core}/@{int}@{bin} @{exec_path} = @{bin_dirs}/fc-cache{,-32,-v*} profile fc-cache @{exec_path} { include include include capability dac_read_search, @{exec_path} mr, /var/cache/fontconfig/{,**} rw, /var/cache/fontconfig/*.cache-@{int} rwk, /var/cache/fontconfig/*.cache-@{int}.LCK rwl, /var/cache/fontconfig/CACHEDIR.TAG.LCK rwl, /var/tmp/mkinitramfs_*/{**,} rwl, # Silencer deny network inet6 stream, deny network inet stream, include if exists } # vim:syntax=apparmor