From 57dfcc758d75c75da963872c5c0f797bdef41a54 Mon Sep 17 00:00:00 2001 From: Alexandre Pujol Date: Sun, 27 Feb 2022 19:11:31 +0000 Subject: [PATCH] Fix pipewrire & chromium. --- apparmor.d/groups/browsers/chromium-chromium | 3 +++ apparmor.d/profiles-m-r/pipewire | 6 +++--- apparmor.d/profiles-m-r/pipewire-pulse | 6 +++--- 3 files changed, 9 insertions(+), 6 deletions(-) diff --git a/apparmor.d/groups/browsers/chromium-chromium b/apparmor.d/groups/browsers/chromium-chromium index 2c6c343f..457b4527 100644 --- a/apparmor.d/groups/browsers/chromium-chromium +++ b/apparmor.d/groups/browsers/chromium-chromium @@ -28,6 +28,9 @@ profile chromium-chromium @{exec_path} flags=(attach_disconnected) { include include include + include + + capability sys_ptrace, ptrace (read) peer=chrome-gnome-shell, diff --git a/apparmor.d/profiles-m-r/pipewire b/apparmor.d/profiles-m-r/pipewire index a8f0fc53..596f5725 100644 --- a/apparmor.d/profiles-m-r/pipewire +++ b/apparmor.d/profiles-m-r/pipewire @@ -1,6 +1,6 @@ # apparmor.d - Full set of apparmor profiles -# Copyright (C) 2015-2020 Mikhail Morfikov -# Copyright (C) 2021 Alexandre Pujol +# Copyright (C) 2015-2022 Mikhail Morfikov +# Copyright (C) 2021-2022 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , @@ -13,7 +13,7 @@ profile pipewire @{exec_path} { include include - ptrace (read) peer=pipewire*, + ptrace (read), @{exec_path} mr, diff --git a/apparmor.d/profiles-m-r/pipewire-pulse b/apparmor.d/profiles-m-r/pipewire-pulse index 942e51fe..14bfbbef 100644 --- a/apparmor.d/profiles-m-r/pipewire-pulse +++ b/apparmor.d/profiles-m-r/pipewire-pulse @@ -1,6 +1,6 @@ # apparmor.d - Full set of apparmor profiles -# Copyright (C) 2015-2020 Mikhail Morfikov -# Copyright (C) 2021 Alexandre Pujol +# Copyright (C) 2015-2022 Mikhail Morfikov +# Copyright (C) 2021-2022 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , @@ -15,7 +15,7 @@ profile pipewire-pulse @{exec_path} flags=(attach_disconnected) { capability sys_ptrace, - ptrace (read) peer=pipewire*, + ptrace (read), @{exec_path} mr,