diff --git a/apparmor.d/groups/browsers/firefox b/apparmor.d/groups/browsers/firefox index 8c456137..33916fd0 100644 --- a/apparmor.d/groups/browsers/firefox +++ b/apparmor.d/groups/browsers/firefox @@ -110,12 +110,12 @@ profile firefox @{exec_path} flags=(attach_disconnected) { dbus send bus=session path=/org/mozilla/firefox/Remote interface=org.mozilla.firefox member=OpenURL - peer=(name=org.mozilla.firefox.* label=@{profile_name}), + peer=(name=org.mozilla.firefox.*, label=@{profile_name}), dbus receive bus=session path=/org/mozilla/firefox/Remote interface=org.mozilla.firefox member=OpenURL - peer=(name=:* label=@{profile_name}), + peer=(name=:*, label=@{profile_name}), dbus bind bus=session name=org.mpris.MediaPlayer2.firefox.*, diff --git a/apparmor.d/groups/systemd/loginctl b/apparmor.d/groups/systemd/loginctl index 36564e3a..aed5eda2 100644 --- a/apparmor.d/groups/systemd/loginctl +++ b/apparmor.d/groups/systemd/loginctl @@ -24,12 +24,12 @@ profile loginctl @{exec_path} { dbus (send) bus=system path=/org/freedesktop/login[0-9]* interface=org.freedesktop.login[0-9]*.Manager member={ListSessions,GetSession} - peer=(name=org.freedesktop.login[0-9]* label=systemd-logind), + peer=(name=org.freedesktop.login[0-9]*, label=systemd-logind), dbus (send) bus=system path=/org/freedesktop/login[0-9]*/session/** interface=org.freedesktop.DBus.Properties member={Get,GetAll} - peer=(name=org.freedesktop.login[0-9]* label=systemd-logind), + peer=(name=org.freedesktop.login[0-9]*, label=systemd-logind), include if exists } diff --git a/apparmor.d/profiles-m-r/rustdesk b/apparmor.d/profiles-m-r/rustdesk index 44e28256..69fc1077 100644 --- a/apparmor.d/profiles-m-r/rustdesk +++ b/apparmor.d/profiles-m-r/rustdesk @@ -120,7 +120,7 @@ profile rustdesk @{exec_path} { owner @{HOME}/.xsession-errors w, # Do not reveal username (pop-up only) - deny /etc/passwd r, +# deny /etc/passwd r, # It's possible to disable root-based service ('systemctl disable rustdesk.service') and use RD only on-demand (or as client-only). After that, sudo isn't necessary. # deny /{,usr/}bin/sudo x,