diff --git a/apparmor.d/groups/lxqt/lxqt-panel b/apparmor.d/groups/lxqt/lxqt-panel index 2caf6b69..9bdd4322 100644 --- a/apparmor.d/groups/lxqt/lxqt-panel +++ b/apparmor.d/groups/lxqt/lxqt-panel @@ -13,6 +13,7 @@ profile lxqt-panel @{exec_path} { include include include + include include include @@ -25,20 +26,16 @@ profile lxqt-panel @{exec_path} { @{exec_path} mr, - @{bin}/exo-open rix, + @{open_path} rix, @{bin}/nm-applet rPx, @{bin}/nm-connection-editor rPx, - @{bin}/xdg-open rPx, @{bin}/ControlPanel rPx, - /usr/lib{,32,64}/lxqt-panel/*.so mr, # LXQT-Plugins - /usr/lib{,32,64}/lxqt-config/*.so mr, # LXQT-Plugins + @{lib}/lxqt-panel/*.so mr, # LXQT-Plugins + @{lib}/lxqt-config/*.so mr, # LXQT-Plugins - /usr/share/lxqt/helpers/*.desktop r, - /usr/share/lxqt/panel/plugins/{,*.desktop} r, /usr/share/desktop-directories/{,**} r, - /usr/share/X11/locale/locale.alias r, - /usr/share/lxqt/themes/{,**} r, + /usr/share/lxqt/{,**} r, /etc/fstab r, /etc/udev/udev.conf r, @@ -50,21 +47,20 @@ profile lxqt-panel @{exec_path} { /var/lib/dbus/machine-id r, - owner @{HOME}/.config/menus/*.menu rw, - owner @{HOME}/.config/menus/applications-merged/ r, owner @{HOME}/Desktop/*.desktop rw, owner @{HOME}/Desktop/#@{int} rw, owner @{HOME}/Desktop/*.desktop l -> @{HOME}/Desktop/#@{int}, - owner @{HOME}/.local/share/desktop-directories/*.directory r, - owner @{HOME}/.local/share/gvfs-metadata/{,*} r, - owner @{user_config_dirs}/lxqt/#* rw, + owner @{user_config_dirs}/menus/*.menu rw, + owner @{user_config_dirs}/menus/applications-merged/ r, + owner @{user_config_dirs}/share/desktop-directories/*.directory r, + owner @{user_config_dirs}/share/gvfs-metadata/{,*} r, + owner @{user_config_dirs}/lxqt/#@{int} rw, owner @{user_config_dirs}/lxqt/panel.conf rw, owner @{user_config_dirs}/lxqt/panel.conf.lock rwk, owner @{user_config_dirs}/lxqt/panel.conf.@{rand6} rw, - owner @{user_config_dirs}/lxqt/panel.conf.@{rand6} l -> @{user_config_dirs}/lxqt/#*, + owner @{user_config_dirs}/lxqt/panel.conf.@{rand6} l -> @{user_config_dirs}/lxqt/#@{int}, owner @{user_config_dirs}/pulse/{,**} rwk, - owner @{user_config_dirs}/ibus/bus/{,**} rw, @{run}/udev/data/* r,