# apparmor.d - Full set of apparmor profiles # Copyright (C) 2021 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = @{libexec}/tracker-extract-3 profile tracker-extract @{exec_path} { include include include include include include include include network netlink raw, @{exec_path} mr, /usr/share/applications/*.desktop r, /usr/share/dconf/profile/gdm r, /usr/share/glib-2.0/schemas/gschemas.compiled r, /usr/share/hwdata/*.ids r, /usr/share/ladspa/rdf/{,**} r, /usr/share/mime/mime.cache r, /usr/share/osinfo/{,**} r, /usr/share/poppler/{,**} r, /usr/share/tracker3-miners/{,**} r, /usr/share/tracker3/{,**} r, /etc/libva.conf r, /var/lib/gdm{3,}/.cache/ rw, /var/lib/gdm{3,}/.cache/tracker3/{,**} rw, /var/lib/gdm{3,}/greeter-dconf-defaults r, # Allow to search user files owner @{HOME}/{,**} r, owner @{MOUNTS}/{,**} r, owner /tmp/*/{,**} r, owner /tmp/tracker-extract-3-files.*/{,*} rw, owner @{user_cache_dirs}/tracker3/files/{,**} rwk, owner @{user_share_dirs}/gvfs-metadata/** r, owner @{run}/user/@{uid}/bus rw, @{run}/blkid/blkid.tab r, @{run}/udev/data/c235:* r, @{run}/udev/data/c236:* r, @{run}/udev/data/c50[0-9]:[0-9]* r, @{run}/udev/data/c51[0-9]:[0-9]* r, @{run}/mount/utab r, owner @{PROC}/@{pid}/fd/ r, owner @{PROC}/@{pid}/mountinfo r, /dev/dri/renderD128 rw, /dev/media[0-9]* r, /dev/video[0-9]* rw, include if exists }