diff --git a/apparmor.d/profiles-a-f/evince b/apparmor.d/profiles-a-f/evince index 0190d419..de2ea096 100644 --- a/apparmor.d/profiles-a-f/evince +++ b/apparmor.d/profiles-a-f/evince @@ -24,12 +24,15 @@ profile evince @{exec_path} { /{usr/,}bin/{,ba,da}sh rix, /{usr/,}bin/gio-launch-desktop rPx, + /usr/share/djvu/{,**} r, /usr/share/evince/{,**} r, + /usr/share/ghostscript/{,**} r, /usr/share/poppler/{,**} r, /usr/share/thumbnailers/{,*} r, /usr/share/themes/{,**} r, owner @{user_share_dirs}/ r, + owner @{user_share_dirs}/gvfs-metadata/{,*} r, owner @{user_cache_dirs}/thumbnails/{,**} rw, owner @{user_config_dirs}/evince/{,*} rw, @@ -42,5 +45,7 @@ profile evince @{exec_path} { /dev/tty rw, + deny /{usr/,}lib/ r, # asks when viewing PostScript files + include if exists }