From d38c57384494979fce2fa60977d9e94a223e21d2 Mon Sep 17 00:00:00 2001 From: Alexandre Pujol Date: Sat, 31 Jul 2021 19:16:42 +0100 Subject: [PATCH] Add gnome-disk-image-mounter. --- .../groups/gnome/gnome-disk-image-mounter | 34 +++++++++++++++++++ 1 file changed, 34 insertions(+) create mode 100644 apparmor.d/groups/gnome/gnome-disk-image-mounter diff --git a/apparmor.d/groups/gnome/gnome-disk-image-mounter b/apparmor.d/groups/gnome/gnome-disk-image-mounter new file mode 100644 index 00000000..a9a4de09 --- /dev/null +++ b/apparmor.d/groups/gnome/gnome-disk-image-mounter @@ -0,0 +1,34 @@ +# apparmor.d - Full set of apparmor profiles +# Copyright (C) 2021 Alexandre Pujol +# SPDX-License-Identifier: GPL-2.0-only + +abi , + +include + +@{exec_path} = /{usr/,}bin/gnome-disk-image-mounter +profile gnome-disk-image-mounter @{exec_path} { + include + include + include + + @{exec_path} mr, + + /usr/share/glib-2.0/schemas/gschemas.compiled r, + /usr/share/X11/xkb/{,**} r, + + # Allow to mount user files + owner @{HOME}/{,**} r, + owner @{MOUNTS}/*/{,**} r, + owner /tmp/*/{,**} r, + + include + owner @{run}/user/@{uid}/dconf/ rw, + owner @{run}/user/@{uid}/dconf/user rw, + + owner @{PROC}/@{pid}/mountinfo r, + + @{run}/mount/utab r, + + include if exists +} \ No newline at end of file