From 2c2f6e55577c4b2056569d10cf1da45512f84625 Mon Sep 17 00:00:00 2001 From: nobodysu Date: Tue, 2 Aug 2022 19:31:00 +0300 Subject: [PATCH] rearrangement --- apparmor.d/abstractions/dbus-gtk | 4 ---- apparmor.d/groups/apps/thunderbird | 5 ++++- apparmor.d/profiles-m-r/qbittorrent | 2 ++ 3 files changed, 6 insertions(+), 5 deletions(-) diff --git a/apparmor.d/abstractions/dbus-gtk b/apparmor.d/abstractions/dbus-gtk index d6aa8be9..6d66796c 100644 --- a/apparmor.d/abstractions/dbus-gtk +++ b/apparmor.d/abstractions/dbus-gtk @@ -44,7 +44,3 @@ interface=org.a11y.atspi.DeviceEventController member={GetKeystrokeListeners,GetDeviceEventListeners} peer=(name=org.a11y.atspi.Registry), - - /etc/gtk-3.[0-9]/settings.ini r, - - owner /tmp/dbus-[0-9a-zA-Z]* rw, diff --git a/apparmor.d/groups/apps/thunderbird b/apparmor.d/groups/apps/thunderbird index 3d21e05b..74fc6fb0 100644 --- a/apparmor.d/groups/apps/thunderbird +++ b/apparmor.d/groups/apps/thunderbird @@ -76,6 +76,8 @@ profile thunderbird @{exec_path} { dbus (bind) bus=session name=org.mozilla.thunderbird.*, + owner /tmp/dbus-[0-9a-zA-Z]* rw, + @{exec_path} mrix, @{MOZ_LIBDIR}/thunderbird-wrapper-helper.sh rix, @@ -141,9 +143,10 @@ profile thunderbird @{exec_path} { /usr/share/qt5ct/** r, # gnome-tiny + /etc/gtk-3.[0-9]/settings.ini r, /etc/gnome/defaults.list r, - @{run}/mount/utab r, /usr/share/gvfs/remote-volume-monitors/{,*} r, + @{run}/mount/utab r, deny @{sys}/devices/system/cpu/present r, deny @{sys}/devices/system/cpu/cpufreq/policy[0-9]/cpuinfo_max_freq r, diff --git a/apparmor.d/profiles-m-r/qbittorrent b/apparmor.d/profiles-m-r/qbittorrent index 458697f8..e02bb132 100644 --- a/apparmor.d/profiles-m-r/qbittorrent +++ b/apparmor.d/profiles-m-r/qbittorrent @@ -108,6 +108,7 @@ profile qbittorrent @{exec_path} { dbus (bind) bus=session name=org.kde.StatusNotifierItem-*, + owner /tmp/dbus-[0-9a-zA-Z]* rw, owner @{run}/user/@{uid}/at-spi/bus{,_[0-9]*} rw, @{exec_path} mr, @@ -176,6 +177,7 @@ profile qbittorrent @{exec_path} { owner @{run}/user/@{uid}/ICEauthority r, # gnome-tiny + /etc/gtk-3.[0-9]/settings.ini r, /usr/share/gvfs/remote-volume-monitors/{,*} r, /usr/share/glib-2.0/schemas/gschemas.compiled r,