# vim:syntax=apparmor # ------------------------------------------------------------------ # # Copyright (C) 2017-2021 Mikhail Morfikov # # This program is free software; you can redistribute it and/or # modify it under the terms of version 2 of the GNU General Public # License published by the Free Software Foundation. # # ------------------------------------------------------------------ abi , include @{exec_path} = /{usr/,}bin/gpg profile gpg @{exec_path} { include include include include @{exec_path} mrix, /{usr/,}bin/gpgconf rPx, /{usr/,}bin/gpg-connect-agent rPx, /{usr/,}bin/gpg-agent rPx, /{usr/,}bin/dirmngr rPx, /{usr/,}bin/gpgsm rPx, /{usr/,}lib/gnupg/scdaemon rPx, # GPG config files owner @{HOME}/ r, owner @{HOME}/.gnupg/ rw, owner @{HOME}/.gnupg/** rwkl -> @{HOME}/.gnupg/**, owner /var/lib/*/gnupg/ rw, owner /var/lib/*/gnupg/** rwkl -> /var/lib/*/gnupg/**, owner /var/lib/*/.gnupg/ rw, owner /var/lib/*/.gnupg/** rwkl -> /var/lib/*/.gnupg/**, # For flatpak owner /tmp/ostree-gpg-*/ r, owner /tmp/ostree-gpg-*/** rwkl -> /tmp/ostree-gpg-*/**, # For ToR Browser owner @{HOME}/.local/share/torbrowser/gnupg_homedir/ r, owner @{HOME}/.local/share/torbrowser/gnupg_homedir/** rwkl -> @{HOME}/.local/share/torbrowser/gnupg_homedir/**, # For spamassassin owner /var/lib/spamassassin/sa-update-keys/** rwkl -> /var/lib/spamassassin/sa-update-keys/**, # For lintian owner /tmp/temp-lintian-lab-*/**/debian/upstream/signing-key.asc r, owner /tmp/lintian-pool-*/**/debian/upstream/signing-key.asc r, owner /tmp/*/.#lk0x[0-9a-f]*.*.@{pid} rw, owner /tmp/*/.#lk0x[0-9a-f]*.*.@{pid}x rwl -> /tmp/*/.#lk0x[0-9a-f]*.*.@{pid}, owner /tmp/*/trustdb.gpg rw, owner /tmp/*/trustdb.gpg.lock rwl -> /tmp/*/.#lk0x[0-9a-f]*.*.@{pid}, owner /tmp/*/pubring.kbx rw, owner /tmp/*/pubring.kbx.lock rwl -> /tmp/*/.#lk0x[0-9a-f]*.*.@{pid}, owner /tmp/*/gnupg_spawn_agent_sentinel.lock rwl -> /tmp/*/.#lk0x[0-9a-f]*.*.@{pid}, owner /tmp/*.gpg rw, owner /tmp/*.gpg~ w, owner /tmp/*.gpg.tmp rw, owner /tmp/*.gpg.lock rwl -> /tmp/.#lk0x[0-9a-f]*.*.@{pid}, owner /tmp/.#lk0x[0-9a-f]*.*.@{pid} rw, owner /tmp/.#lk0x[0-9a-f]*.*.@{pid}x rwl -> /tmp/.#lk0x[0-9a-f]*.*.@{pid}, owner @{run}/user/[0-9]*/gnupg/d.*/ rw, # Verify files owner @{HOME}/** r, owner /media/*/** r, owner @{PROC}/@{pid}/task/@{tid}/stat rw, owner @{PROC}/@{pid}/task/@{tid}/comm rw, owner @{PROC}/@{pid}/fd/ r, /etc/inputrc r, # file_inherit /tmp/#[0-9]*[0-9] rw, include if exists }