diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index a5d953b4..bc048f90 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -9,7 +9,7 @@ jobs: matrix: mode: - default - # - full-system-policy + - full-system-policy steps: - name: Check out repository code diff --git a/apparmor.d/groups/_full/bwrap b/apparmor.d/groups/_full/bwrap index 6744857c..e797d902 100644 --- a/apparmor.d/groups/_full/bwrap +++ b/apparmor.d/groups/_full/bwrap @@ -51,7 +51,7 @@ profile bwrap @{exec_path} flags=(attach_disconnected,mediate_deleted) { @{bin}/** Px -> bwrap//&bwrap-app, @{bin}/xdg-dbus-proxy Px -> bwrap//&xdg-dbus-proxy, - @{lib}/** Px -> bwrap//&bwrap-app, + # @{lib}/** Px -> bwrap//&bwrap-app, /opt/*/** Px -> bwrap//&bwrap-app, /usr/share/*/* Px -> bwrap//&bwrap-app, diff --git a/apparmor.d/groups/_full/default b/apparmor.d/groups/_full/default index bb8331f6..a400b7ab 100644 --- a/apparmor.d/groups/_full/default +++ b/apparmor.d/groups/_full/default @@ -49,7 +49,7 @@ profile default @{exec_path} flags=(attach_disconnected,mediate_deleted) { @{bin}/more rPx -> child-pager, @{bin}/pager rPx -> child-pager, - @{open_path} rPx -> child-open, +# @{open_path} rPx -> child-open, audit @{bin}/** Pix, audit @{lib}/** Pix,