# apparmor.d - Full set of apparmor profiles # Copyright (C) 2024 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only # LOGPROF-SUGGEST: no # Minimal set of rules for pkexec. abi , include include include include include capability audit_write, capability dac_override, capability dac_read_search, capability net_admin, capability setgid, capability setuid, capability sys_ptrace, capability sys_resource, network netlink raw, # PAM #aa:dbus talk bus=system name=org.freedesktop.PolicyKit1.Authority label=polkitd @{bin}/pkexec mr, /etc/shells r, owner @{PROC}/@{pid}/loginuid r, owner /dev/tty@{int} rw, deny @{user_share_dirs}/gvfs-metadata/* r, include if exists # vim:syntax=apparmor