# apparmor.d - Full set of apparmor profiles # Copyright (C) 2019-2022 Mikhail Morfikov # Copyright (C) 2022 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = /{usr/,}bin/xdg-settings profile xdg-settings @{exec_path} { include include @{exec_path} r, /{usr/,}bin/{,ba,da}sh rix, /{usr/,}bin/{,e}grep rix, /{usr/,}bin/basename rix, /{usr/,}bin/cat rix, /{usr/,}bin/cut rix, /{usr/,}bin/mktemp rix, /{usr/,}bin/mv rix, /{usr/,}bin/readlink rix, /{usr/,}bin/sed rix, /{usr/,}bin/sort rix, /{usr/,}bin/uname rix, /{usr/,}bin/wc rix, /{usr/,}bin/which{,.debianutils} rix, /{usr/,}bin/dbus-launch rCx -> dbus, /{usr/,}bin/dbus-send rCx -> dbus, /{usr/,}bin/xdg-mime rPx, /{usr/,}bin/xprop rPx, /usr/share/terminfo/x/xterm-256color r, /etc/xdg/xfce4/helpers.rc r, /etc/machine-id r, /var/lib/dbus/machine-id r, /var/lib/flatpak/exports/share/applications/{,*} r, /var/lib/snapd/desktop/applications/{,*} r, # freedesktop.org-strict /usr/share/applications/{,*} r, /usr/share/ubuntu/applications/ r, owner @{user_share_dirs}/applications/ r, owner @{user_share_dirs}/applications/*.desktop r, owner @{HOME}/ r, owner @{HOME}/.Xauthority r, owner @{user_config_dirs}/xfce4/helpers.rc{,.*} rw, owner @{run}/user/@{uid}/ r, owner @{PROC}/@{pid}/fd/ r, profile dbus { include include /{usr/,}bin/dbus-launch mr, /{usr/,}bin/dbus-send mr, /{usr/,}bin/dbus-daemon rPx, # for dbus-launch owner @{HOME}/.dbus/session-bus/@{hex}-[0-9] w, @{HOME}/.Xauthority r, } include if exists }