diff --git a/apparmor.d/groups/cron/crontab b/apparmor.d/groups/cron/crontab index 82d3c543..c5aaf554 100644 --- a/apparmor.d/groups/cron/crontab +++ b/apparmor.d/groups/cron/crontab @@ -29,7 +29,9 @@ profile crontab @{exec_path} { @{bin}/nvim rCx -> editor, /etc/cron.{allow,deny} r, + /etc/environment r, /etc/pam.d/* r, + /etc/security/*.conf r, /var/spool/cron/ r, /var/spool/cron/crontabs/ rw, diff --git a/apparmor.d/groups/gpg/scdaemon b/apparmor.d/groups/gpg/scdaemon index eeb1a618..92be0bdc 100644 --- a/apparmor.d/groups/gpg/scdaemon +++ b/apparmor.d/groups/gpg/scdaemon @@ -20,6 +20,7 @@ profile scdaemon @{exec_path} { @{exec_path} mr, owner @{HOME}/@{XDG_GPG_DIR}/scdaemon.conf r, + owner @{HOME}/@{XDG_GPG_DIR}common.conf r, owner @{HOME}/@{XDG_GPG_DIR}/reader_@{int}.status rw, owner @{run}/user/@{uid}/gnupg/S.scdaemon rw, diff --git a/apparmor.d/profiles-m-r/pinentry b/apparmor.d/profiles-m-r/pinentry index c30bc5de..c466f05a 100644 --- a/apparmor.d/profiles-m-r/pinentry +++ b/apparmor.d/profiles-m-r/pinentry @@ -15,6 +15,7 @@ profile pinentry @{exec_path} { @{bin}/pinentry-* rPx, @{sh_path} rix, + @{bin}/ldd rix, /etc/pinentry/preexec r,