# apparmor.d - Full set of apparmor profiles # Copyright (C) 2021-2024 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = /usr/share/libalpm/scripts/gio-querymodules profile pacman-hook-gio @{exec_path} { include capability dac_read_search, @{exec_path} mr, @{bin}/bash rix, @{bin}/rmdir rix, @{bin}/gio-querymodules rPx, @{lib}/gio/modules/giomodule.cache{,.[0-9A-Z]*} rw, @{lib}/gtk-{3,4}.0/**/*/ rw, /usr/lib/gio/modules/ rw, /dev/tty rw, # Inherit Silencer deny network inet6 stream, deny network inet stream, include if exists } # vim:syntax=apparmor