diff --git a/apparmor.d/profiles-a-l/aa-notify b/apparmor.d/profiles-a-l/aa-notify new file mode 100644 index 00000000..96aeb9a6 --- /dev/null +++ b/apparmor.d/profiles-a-l/aa-notify @@ -0,0 +1,34 @@ +# apparmor.d - Full set of apparmor profiles +# Copyright (C) 2021 Alexandre Pujol +# SPDX-License-Identifier: GPL-2.0-only + +abi , + +include + +@{exec_path} = /{usr/,}bin/aa-notify +profile aa-notify @{exec_path} flags=(complain) { + include + include + include + + ptrace (read), + + @{exec_path} mr, + + /etc/apparmor/*.conf r, + /etc/inputrc r, + + /usr/share/terminfo/x/xterm-256color r, + /usr/share/terminfo/d/dumb r, + /var/log/audit/audit.log r, + + owner /tmp/[a-z0-9]* r, + owner /tmp/apparmor-bugreport-[a-z0-9]*.txt rw, + + @{PROC}/ r, + @{PROC}/@{pid}/stat r, + @{PROC}/@{pid}/cmdline r, + + include if exists +}