diff --git a/apparmor.d/groups/gnome/epiphany-search-provider b/apparmor.d/groups/gnome/epiphany-search-provider new file mode 100644 index 00000000..6a316a27 --- /dev/null +++ b/apparmor.d/groups/gnome/epiphany-search-provider @@ -0,0 +1,49 @@ +# apparmor.d - Full set of apparmor profiles +# Copyright (C) 2023 Alexandre Pujol +# SPDX-License-Identifier: GPL-2.0-only + +abi , + +include + +@{exec_path} = @{lib}/epiphany-search-provider +profile epiphany-search-provider @{exec_path} { + include + include + include + include + include + include + include + include + include + include + include + include + include + + network inet dgram, + network inet6 dgram, + network inet stream, + network inet6 stream, + network netlink raw, + + @{exec_path} mr, + + @{lib}/webkitgtk-*/WebKitNetworkProcess rix, + + owner @{user_cache_dirs}/epiphany/{,**} rwk, + owner @{user_share_dirs}/epiphany/{,**} rwk, + + @{sys}/fs/cgroup/user.slice/user-@{uid}.slice/user@@{uid}.service/session.slice/dbus.service/memory.* r, + + @{PROC}/driver/nvidia/params r, + @{PROC}/modules r, + @{PROC}/sys/dev/i915/perf_stream_paranoid r, + @{PROC}/zoneinfo r, + owner @{PROC}/@{pid}/cgroup r, + owner @{PROC}/@{pid}/cmdline r, + owner @{PROC}/@{pid}/comm r, + + include if exists +} \ No newline at end of file diff --git a/apparmor.d/groups/gnome/epiphany-webapp-provider b/apparmor.d/groups/gnome/epiphany-webapp-provider new file mode 100644 index 00000000..2b93d547 --- /dev/null +++ b/apparmor.d/groups/gnome/epiphany-webapp-provider @@ -0,0 +1,18 @@ +# apparmor.d - Full set of apparmor profiles +# Copyright (C) 2023 Alexandre Pujol +# SPDX-License-Identifier: GPL-2.0-only + +abi , + +include + +@{exec_path} = @{lib}/epiphany-webapp-provider +profile epiphany-webapp-provider @{exec_path} { + include + + @{exec_path} mr, + + owner @{user_share_dirs}/ r, + + include if exists +} \ No newline at end of file diff --git a/dists/flags/main.flags b/dists/flags/main.flags index d25e91be..66a0bfcd 100644 --- a/dists/flags/main.flags +++ b/dists/flags/main.flags @@ -92,6 +92,7 @@ drkonqi complain e2fsck complain e2scrub_all attach_disconnected,complain element complain +epiphany-search-provider complain epiphany-webapp-provider complain etckeeper complain fail2ban-client attach_disconnected,complain