diff --git a/apparmor.d/profiles-a-f/flatpak b/apparmor.d/profiles-a-f/flatpak index 853f665f..f992f15e 100644 --- a/apparmor.d/profiles-a-f/flatpak +++ b/apparmor.d/profiles-a-f/flatpak @@ -11,6 +11,7 @@ profile flatpak @{exec_path} flags=(attach_disconnected,mediate_deleted,complain include include include + include include include include diff --git a/apparmor.d/profiles-a-f/flatpak-app b/apparmor.d/profiles-a-f/flatpak-app index fee270b4..e607fe42 100644 --- a/apparmor.d/profiles-a-f/flatpak-app +++ b/apparmor.d/profiles-a-f/flatpak-app @@ -58,6 +58,7 @@ profile flatpak-app flags=(attach_disconnected,mediate_deleted) { signal (receive) set=(int) peer=flatpak-portal, @{bin}/** rmix, + @{lib}/kf5/kioslave5 rPx, @{lib}/** rmix, /app/** rmix, /var/lib/flatpak/app/*/**/@{bin}/** rmix, @@ -88,6 +89,8 @@ profile flatpak-app flags=(attach_disconnected,mediate_deleted) { /var/tmp/etilqs_@{hex} rw, @{run}/.userns r, + owner @{run}/user/@{uid}/*.kioworker.socket r, + owner @{run}/user/@{uid}/#@{int} rwl, owner @{run}/flatpak/{,**} rk, owner @{run}/flatpak/app/*/*ipc* rw, owner @{run}/ld-so-cache-dir/* rw,