diff --git a/apparmor.d/abstractions/gnome.d/complete b/apparmor.d/abstractions/gnome.d/complete new file mode 100644 index 00000000..2921a557 --- /dev/null +++ b/apparmor.d/abstractions/gnome.d/complete @@ -0,0 +1,5 @@ +# apparmor.d - Full set of apparmor profiles +# Copyright (C) 2021 Alexandre Pujol +# SPDX-License-Identifier: GPL-2.0-only + + include diff --git a/apparmor.d/abstractions/gtk b/apparmor.d/abstractions/gtk index 334c95cd..f69aee26 100644 --- a/apparmor.d/abstractions/gtk +++ b/apparmor.d/abstractions/gtk @@ -31,6 +31,7 @@ owner @{user_config_dirs}/gtk-3.0/bookmarks r, owner @{user_config_dirs}/gtk-3.0/gtk.css r, owner @{user_config_dirs}/gtk-3.0/colors.css r, + owner @{user_config_dirs}/gtk-3.0/servers r, # for gtk file dialog owner @{user_config_dirs}/gtk-2.0/ rw, diff --git a/apparmor.d/abstractions/python.d/complete b/apparmor.d/abstractions/python.d/complete index 68fcac7a..f381c227 100644 --- a/apparmor.d/abstractions/python.d/complete +++ b/apparmor.d/abstractions/python.d/complete @@ -3,7 +3,14 @@ # 2021 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only + /usr/bin/python{2.[4-7],3,3.[0-9]} r, + /usr/local/lib{,32,64}/python{2.[4-7],3,3.[0-9]}/{site,dist}-packages/**/ r, + owner @{user_lib_dirs}/python{2.[4-7],3,3.[0-9]}/**.{pyc,so} mr, + owner @{user_lib_dirs}/python{2.[4-7],3,3.[0-9]}/**.{egg,py,pth} r, + owner @{user_lib_dirs}/python{2.[4-7],3,3.[0-9]}/{site,dist}-packages/ r, + owner @{user_lib_dirs}/python{2.[4-7],3,3.[0-9]}/{site,dist}-packages/**/ r, + # Silencer /{usr/,}lib/python3/** w, diff --git a/apparmor.d/abstractions/zsh b/apparmor.d/abstractions/zsh index aec66f27..8df08518 100644 --- a/apparmor.d/abstractions/zsh +++ b/apparmor.d/abstractions/zsh @@ -1,5 +1,6 @@ # apparmor.d - Full set of apparmor profiles # Copyright (C) 2018-2021 Mikhail Morfikov +# 2021 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , @@ -15,6 +16,7 @@ /etc/zsh/zlogin r, owner @{HOME}/.zshrc r, + owner @{HOME}/.zshenv r, owner @{HOME}/.zsh_history rw, owner @{HOME}/.zsh_history.LOCK rwk, @@ -22,3 +24,4 @@ owner @{HOME}/.oh-my-zsh/log/update.lock/ w, owner @{HOME}/.zcompdump-* rw, + owner @{user_config_dirs}/zsh/{,**} r,