]> rtime.felk.cvut.cz Git - sojka/debian/lightdm.git/blob - debian/patches/02_fix-apparmor-profile.patch
* debian/patches:
[sojka/debian/lightdm.git] / debian / patches / 02_fix-apparmor-profile.patch
1 --- a/data/apparmor/abstractions/lightdm_chromium-browser
2 +++ b/data/apparmor/abstractions/lightdm_chromium-browser
3 @@ -8,6 +8,7 @@
4  # provided in abstractions/lightdm, this abstraction must be separate from
5  # abstractions/lightdm.
6  
7 +  /usr/lib/chromium/chromium Cx -> chromium,
8    /usr/lib/chromium-browser/chromium-browser Cx -> chromium,
9    /usr/bin/webapp-container Cx -> chromium,
10    /usr/bin/webbrowser-app Cx -> chromium,
11 @@ -53,6 +54,7 @@
12  
13      /selinux/ r,
14  
15 +    /usr/lib/chromium/chrome-sandbox ix,
16      /usr/lib/chromium-browser/chromium-browser-sandbox ix,
17      /usr/lib/@{multiarch}/oxide-qt/chrome-sandbox ix,
18      /opt/google/chrome-*/chrome-sandbox ix,
19 --- a/data/apparmor/abstractions/lightdm
20 +++ b/data/apparmor/abstractions/lightdm
21 @@ -27,7 +27,7 @@
22    owner /dev/shm/** rmw,
23    /etc/ r,
24    /etc/** rmk,
25 -  /etc/gdm/Xsession ix,
26 +  /etc/X11/Xsession ix,
27    /lib/ r,
28    /lib/** rmixk,
29    /lib32/ r,
30 @@ -68,6 +68,7 @@
31    # necessary for writing to sockets, etc.
32    /{,var/}run/** rmkix,
33    /{,var/}run/shm/** wl,
34 +  /{,var/}run/uuid/request w,
35    # libpam-xdg-support/logind
36    owner /{,var/}run/user/*/** rw,
37