diff --git a/apparmor.d/groups/desktop/blueman b/apparmor.d/groups/desktop/blueman index 30af7e3f..d3527585 100644 --- a/apparmor.d/groups/desktop/blueman +++ b/apparmor.d/groups/desktop/blueman @@ -46,6 +46,8 @@ profile blueman @{exec_path} flags=(attach_disconnected) { owner @{user_cache_dirs}/obexd/ rw, owner @{user_cache_dirs}/obexd/* rw, + owner @{user_share_dirs}/gvfs-metadata/{,*} r, + owner @{HOME}/ r, owner @{HOME}/bluetooth*/ r, owner @{HOME}/bluetooth*/* rw, diff --git a/apparmor.d/groups/desktop/dconf b/apparmor.d/groups/desktop/dconf new file mode 100644 index 00000000..2dc3d12b --- /dev/null +++ b/apparmor.d/groups/desktop/dconf @@ -0,0 +1,27 @@ +# apparmor.d - Full set of apparmor profiles +# Copyright (C) 2021 Alexandre Pujol +# SPDX-License-Identifier: GPL-2.0-only + +abi , + +include + +@{exec_path} = /{usr/,}bin/dconf +profile dconf @{exec_path} { + include + + capability sys_nice, + + @{exec_path} mr, + + /etc/dconf/{,**} r, + /etc/dconf/db/** rw, + + owner @{run}/user/@{uid}/dconf/ rw, + owner @{run}/user/@{uid}/dconf/user rw, + + owner @{user_config_dirs}/dconf/ rw, + owner @{user_config_dirs}/dconf/user{,.*} rw, + + include if exists +} \ No newline at end of file