diff --git a/apparmor.d/groups/browsers/firefox b/apparmor.d/groups/browsers/firefox index 33312db5..226d613b 100644 --- a/apparmor.d/groups/browsers/firefox +++ b/apparmor.d/groups/browsers/firefox @@ -190,6 +190,7 @@ profile firefox @{exec_path} { # file_inherit owner /dev/tty[0-9]* rw, + /dev/dri/card[0-9]* rw, /etc/opensc.conf r, diff --git a/apparmor.d/groups/desktop/xwayland b/apparmor.d/groups/desktop/xwayland index 7eb59d4c..14464a55 100644 --- a/apparmor.d/groups/desktop/xwayland +++ b/apparmor.d/groups/desktop/xwayland @@ -15,6 +15,7 @@ profile xwayland @{exec_path} flags=(attach_disconnected) { include signal (receive) set=(term hup) peer=gdm*, + signal (receive) set=(term hup) peer=gnome-shell, @{exec_path} mrix, diff --git a/apparmor.d/profiles-a-l/fsck b/apparmor.d/profiles-a-l/fsck index c93d7459..0b025869 100644 --- a/apparmor.d/profiles-a-l/fsck +++ b/apparmor.d/profiles-a-l/fsck @@ -11,6 +11,9 @@ profile fsck @{exec_path} { include include + capability dac_override, + capability dac_read_search, + @{exec_path} mr, /{usr/,}{s,}bin/e2fsck rPx, diff --git a/apparmor.d/profiles-m-z/openbox b/apparmor.d/profiles-m-z/openbox index 1f478dd3..be2117cd 100644 --- a/apparmor.d/profiles-m-z/openbox +++ b/apparmor.d/profiles-m-z/openbox @@ -64,12 +64,8 @@ profile openbox @{exec_path} { # Apps allowed to run /{usr/,}sbin/* rPUx, /{usr/,}bin/* rPUx, -<<<<<<< HEAD:apparmor.d/profiles-m-z/openbox - /usr/{lib,libexec}/* rPUx, -======= /usr/local/bin/* rPUx, - /usr/libexec/* rPUx, ->>>>>>> ff78b17 (update apparmor profiles):apparmor.d/openbox + /usr/{lib,libexec}/* rPUx, /{usr/,}lib/@{multiarch}/*/** rPUx, /usr/local/lib/python*/dist-packages/ r, diff --git a/apparmor.d/profiles-m-z/virt-manager b/apparmor.d/profiles-m-z/virt-manager index fea5ec5f..e7c83963 100644 --- a/apparmor.d/profiles-m-z/virt-manager +++ b/apparmor.d/profiles-m-z/virt-manager @@ -62,6 +62,7 @@ profile virt-manager @{exec_path} { #owner /var/lib/libvirt/images/ r, # User VM images + owner @{user_share_dirs}/ r, owner @{user_share_dirs}/libvirt/{,**} rw, owner @{HOME}/@{XDG_VM_DIR}/{,**} rw, owner @{MOUNTS}/*/@{XDG_VM_DIR}/{,**} rw,