41 lines
1.1 KiB
Text
41 lines
1.1 KiB
Text
# apparmor.d - Full set of apparmor profiles
|
|
# Copyright (C) 2024 Alexandre Pujol <alexandre@pujol.io>
|
|
# Copyright (C) 2024 Besanon <m231009ts@mailfence.com>
|
|
# SPDX-License-Identifier: GPL-2.0-only
|
|
|
|
abi <abi/3.0>,
|
|
|
|
include <tunables/global>
|
|
|
|
@{exec_path} = @{bin}/lxqt-runner
|
|
profile lxqt-runner @{exec_path} flags=(complain) {
|
|
include <abstractions/base>
|
|
include <abstractions/gtk>
|
|
include <abstractions/video>
|
|
include <abstractions/lxqt>
|
|
include <abstractions/dbus-session-strict>
|
|
include <abstractions/dbus-accessibility-strict>
|
|
include <abstractions/gvfs-open>
|
|
|
|
@{exec_path} mr,
|
|
|
|
/usr/share/icons/ r,
|
|
/usr/share/icons/{,**} r,
|
|
/usr/share/desktop-directories/ r,
|
|
/usr/share/desktop-directories/{,**} r,
|
|
|
|
/etc/xdg/menus/lxqt-applications.menu r,
|
|
|
|
owner @{user_config_dirs}/lxqt/lxqt-runner.conf.lock rwk,
|
|
owner @{user_config_dirs}/lxqt/#@{int} rw,
|
|
owner @{user_config_dirs}/lxqt/lxqt-runner.conf.@{rand6} rwkl -> @{user_config_dirs}/lxqt/#@{int},
|
|
|
|
# only needed if tor is installed on /opt
|
|
owner /opt/*/**/*.png r,
|
|
|
|
owner /tmp/{,**} r,
|
|
|
|
/dev/tty rw,
|
|
|
|
include if exists <local/lxqt-runner>
|
|
}
|