qutebrowser/misc/apparmor/usr.bin.qutebrowser

42 lines
997 B
Plaintext
Raw Normal View History

2014-07-30 12:50:56 +02:00
# AppArmor profile for qutebrowser
# Tested on Debian jessie
#include <tunables/global>
profile qutebrowser /usr/{local/,}bin/qutebrowser {
2014-07-30 12:50:56 +02:00
2014-08-27 12:10:35 +02:00
#include <abstractions/base>
2014-08-27 12:29:03 +02:00
#include <abstractions/nameservice>
2014-08-27 12:45:07 +02:00
#include <abstractions/openssl>
#include <abstractions/ssl_certs>
2014-08-27 12:10:35 +02:00
#include <abstractions/audio>
#include <abstractions/fonts>
#include <abstractions/kde>
#include <abstractions/user-download>
2014-07-30 12:50:56 +02:00
#include <abstractions/X>
2014-08-27 12:10:35 +02:00
2014-07-30 12:50:56 +02:00
capability dac_override,
/usr/{local/,}bin/ r,
/usr/{local/,}bin/qutebrowser rix,
2014-08-27 12:20:48 +02:00
/usr/bin/python3.? r,
2014-08-27 12:10:35 +02:00
2014-07-30 12:50:56 +02:00
/usr/lib/python3/ mr,
/usr/lib/python3/** mr,
/usr/lib/python3.?/ r,
/usr/lib/python3.?/** mr,
2014-08-27 12:20:48 +02:00
/usr/local/lib/python3.?/** r,
2014-08-27 12:45:07 +02:00
2014-08-27 12:50:33 +02:00
/proc/*/mounts r,
2014-08-27 13:01:13 +02:00
owner /tmp/** rwkl,
2015-09-15 10:11:06 +02:00
owner /run/user/*/ rw,
owner /run/user/*/** krw,
2014-07-30 12:50:56 +02:00
2014-08-27 12:10:35 +02:00
@{HOME}/.config/qutebrowser/** krw,
@{HOME}/.local/share/qutebrowser/** krw,
@{HOME}/.cache/qutebrowser/** krw,
@{HOME}/.gstreamer-0.10/* r,
2014-07-30 12:50:56 +02:00
}