# apparmor.d - Full set of apparmor profiles # Copyright (C) 2021 Mikhail Morfikov # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = /{usr/,}lib/gvfs/gvfs-udisks2-volume-monitor @{exec_path} += /usr/libexec/gvfs-udisks2-volume-monitor profile gvfs-udisks2-volume-monitor @{exec_path} { include include include include include network inet stream, network inet6 stream, network netlink raw, signal (send) set=(term, kill) peer=mount, @{exec_path} mr, /{usr/,}bin/lsof rix, /{usr/,}bin/mount rPx, /{usr/,}bin/umount rPx, include owner @{run}/user/[0-9]*/dconf/ w, owner @{run}/user/[0-9]*/dconf/user rw, /etc/fstab r, # Mount points /media/*/ r, /media/*/*/ r, @{HOME}/*/*/ r, @{HOME}/*/*/**/ r, @{HOME}/bluetooth/ r, / r, /usr/share/glib-2.0/schemas/gschemas.compiled r, @{run}/mount/utab r, @{PROC}/ r, owner @{PROC}/@{pid}/fd/ r, owner @{PROC}/@{pid}/mountinfo r, owner @{PROC}/@{pid}/mounts r, owner @{PROC}/@{pid}/cgroup r, @{PROC}/1/cgroup r, @{PROC}/locks r, include if exists }