mirror of
https://github.com/onionshare/onionshare.git
synced 2025-08-01 10:56:22 -04:00
AppArmor profiles for Onionshare, written by Tails developers
This commit is contained in:
parent
cdbdd366ba
commit
338e9d04c1
5 changed files with 71 additions and 0 deletions
26
apparmor/usr.bin.onionshare-gui
Normal file
26
apparmor/usr.bin.onionshare-gui
Normal file
|
@ -0,0 +1,26 @@
|
|||
#include <tunables/global>
|
||||
|
||||
/usr/bin/onionshare-gui flags=(complain) {
|
||||
#include <abstractions/gnome>
|
||||
#include <abstractions/ibus>
|
||||
#include <abstractions/onionshare>
|
||||
|
||||
/usr/bin/ r,
|
||||
/usr/bin/onionshare-gui r,
|
||||
/proc/*/cmdline r,
|
||||
/usr/share/icons/Adwaita/index.theme rwk,
|
||||
|
||||
# Why do these still emit audit journal entries?
|
||||
owner @{HOME}/.config/ibus/bus/ rw,
|
||||
owner @{HOME}/.config/ibus/bus/* rw,
|
||||
deny @{HOME}/.ICEauthority r,
|
||||
|
||||
deny /{,lib/live/mount/rootfs/filesystem.squashfs/}etc/machine-id r,
|
||||
deny /var/lib/dbus/machine-id.* rw,
|
||||
|
||||
# Accessibility support
|
||||
owner /{,var/}run/user/*/at-spi2-*/ rw,
|
||||
owner /{,var/}run/user/*/at-spi2-*/** rw,
|
||||
|
||||
#include <local/usr.bin.onionshare-gui>
|
||||
}
|
Loading…
Add table
Add a link
Reference in a new issue