diff --git a/contrib/apparmor/usr.bin.qutebrowser b/contrib/apparmor/usr.bin.qutebrowser new file mode 100644 index 000000000..2dc5398fe --- /dev/null +++ b/contrib/apparmor/usr.bin.qutebrowser @@ -0,0 +1,39 @@ +# AppArmor profile for qutebrowser +# Tested on Debian jessie + +#include + +profile qutebrowser /usr/{local/,}bin/qutebrowser { + + #include + #include + #include + #include + #include + #include + #include + #include + #include + + capability dac_override, + + /usr/{local/,}bin/ r, + /usr/{local/,}bin/qutebrowser rix, + /usr/bin/python3.? r, + + /usr/lib/python3/ mr, + /usr/lib/python3/** mr, + /usr/lib/python3.?/ r, + /usr/lib/python3.?/** mr, + /usr/local/lib/python3.?/** r, + + /proc/*/mounts r, + owner /tmp/** rwkl, + + @{HOME}/.config/qutebrowser/** krw, + @{HOME}/.local/share/qutebrowser/** krw, + @{HOME}/.cache/qutebrowser/** krw, + @{HOME}/.gstreamer-0.10/* r, + +} +