# apparmor.d - Full set of apparmor profiles # Copyright (C) 2019-2021 Mikhail Morfikov # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = /{usr/,}bin/xhost profile xhost @{exec_path} { include include unix (send, receive, connect) type=stream peer=(addr=@/tmp/.X11-unix/*, label=xorg), @{exec_path} mr, owner @{HOME}/.Xauthority r, owner @{run}/user/@{uid}/gdm/Xauthority r, /tmp/.X11-unix/* rw, # file_inherit /dev/tty[0-9]* rw, owner @{HOME}/.xsession-errors w, include if exists }