diff --git a/apparmor.d/groups/children/child-open-any b/apparmor.d/groups/children/child-open-any index ea21f848..b0c0b053 100644 --- a/apparmor.d/groups/children/child-open-any +++ b/apparmor.d/groups/children/child-open-any @@ -11,11 +11,11 @@ abi , include -profile child-open-any flags=(attach_disconnected) { +profile child-open-any flags=(attach_disconnected,mediate_deleted) { include include - @{open_path} mr, + @{open_path} mrix, @{sh_path} r, @@ -32,6 +32,8 @@ profile child-open-any flags=(attach_disconnected) { /usr/ r, /usr/local/bin/ r, + owner @{run}/user/@{uid}/kioclient@{rand6}.@{int}.kioworker.socket rwl -> @{run}/user/@{uid}/#@{int}, + /dev/tty rw, include if exists