# apparmor.d - Full set of apparmor profiles # Copyright (C) 2021-2024 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = @{lib}/systemd/user-environment-generators/* profile systemd-generator-user-environment @{exec_path} flags=(attach_disconnected) { include include include capability net_admin, @{exec_path} mr, @{sh_path} rix, @{bin}/flatpak rPUx, @{bin}/gpgconf rPx, @{bin}/{m,g,}awk rix, @{etc_ro}/environment r, @{etc_ro}/environment.d/{,**} r, /snap/snapd/@{int}/usr/lib/environment.d/{,*.conf} r, owner @{user_config_dirs}/environment.d/{,*.conf} r, /dev/tty rw, include if exists } # vim:syntax=apparmor