# vim:syntax=apparmor # ------------------------------------------------------------------ # # Copyright (C) 2002-2009 Novell/SUSE # Copyright (C) 2009-2011 Canonical Ltd. # # This program is free software; you can redistribute it and/or # modify it under the terms of version 2 of the GNU General Public # License published by the Free Software Foundation. # # ------------------------------------------------------------------ #include <abstractions/base> #include <abstractions/fonts> #include <abstractions/X> #include <abstractions/freedesktop.org> #include <abstractions/xdg-desktop> #include <abstractions/user-tmp> #include <abstractions/wayland> # systemwide gtk defaults /etc/gnome/gtkrc* r, /etc/gtk/* r, /usr/lib{,32,64}/gtk/** mr, /usr/lib/@{multiarch}/gtk/** mr, /usr/lib{,32,64}/gtk-[0-9]*/** mr, /usr/lib/@{multiarch}/gtk-[0-9]*/** mr, /usr/share/themes/ r, /usr/share/themes/** r, # communitheme snap /snap/communitheme/*/share/themes/ r, /snap/communitheme/*/share/themes/** r, # for gnome 1 applications /etc/orbitrc r, # gtk-2 needed some new rights /etc/fonts/* r, /etc/gtk-*/* r, /etc/pango/* r, /usr/lib{,32,64}/pango/** mr, /usr/lib{,32,64}/gtk-*/** mr, /usr/lib{,32,64}/gdk-pixbuf-*/** mr, /usr/lib/@{multiarch}/pango/** mr, /usr/lib/@{multiarch}/gtk-*/** mr, /usr/lib/@{multiarch}/gdk-pixbuf-*/** mr, # per-user gtk configuration owner @{HOME}/.config/gtk-3.0/* r, owner @{HOME}/.gnome/Gnome r, owner @{HOME}/.gtk r, owner @{HOME}/.gtkrc r, owner @{HOME}/.gtkrc-2.0 r, owner @{HOME}/.gtk-bookmarks r, owner @{HOME}/.themes/ r, owner @{HOME}/.themes/** r, # for gtk file dialog owner @{HOME}/.config/gtk-2.0/** r, owner @{HOME}/.config/gtk-2.0/gtkfilechooser.ini* rw, # from evolution-mail owner @{HOME}/.gconfd/lock/* r, owner @{HOME}/.gnome/application-info r, # per-user font business owner @{HOME}/.fonts.cache-* rwl, # icon caches /var/cache/**/icon-theme.cache r, /usr/share/**/icon-theme.cache r, # GLib schemas /usr/{local/,}share/glib-[0-9]*/schemas/ r, /usr/{local/,}share/glib-[0-9]*/schemas/** r, # gnome VFS modules /etc/gnome-vfs-2.0/modules/ r, /etc/gnome-vfs-2.0/modules/* r, /usr/lib/gnome-vfs-2.0/modules/*.so mr, /usr/lib/@{multiarch}/gnome-vfs-2.0/modules/*.so mr, # gvfs /usr/share/gvfs/remote-volume-monitors/ r, /usr/share/gvfs/remote-volume-monitors/* r, @{PROC}/@{pid}/mounts r, # printing /etc/papersize r, /etc/cups/lpoptions r, /usr/share/cups/charmaps/** r, # holds MIT-MAGIC-COOKIE for gnome owner /{,var/}run/gdm/auth*/database r, # mime-types /etc/gnome/defaults.list r, /etc/xdg/*-mimeapps.list r, /usr/share/gnome/applications/ r, /usr/share/gnome/applications/mimeinfo.cache r, # Allow connecting to the GNOME vfs socket (still need corresponding DBus # rules) unix (send, receive, connect) type=stream peer=(addr="@/dbus-vfs-daemon/socket-*"),
Name | Type | Size | Permission | Actions |
---|---|---|---|---|
apparmor_api | Folder | 0755 |
|
|
lxc | Folder | 0755 |
|
|
ubuntu-browsers.d | Folder | 0755 |
|
|
X | File | 1.86 KB | 0644 |
|
apache2-common | File | 869 B | 0644 |
|
aspell | File | 308 B | 0644 |
|
audio | File | 1.72 KB | 0644 |
|
authentication | File | 1.55 KB | 0644 |
|
base | File | 6.21 KB | 0644 |
|
bash | File | 1.48 KB | 0644 |
|
consoles | File | 798 B | 0644 |
|
cups-client | File | 714 B | 0644 |
|
dbus | File | 593 B | 0644 |
|
dbus-accessibility | File | 630 B | 0644 |
|
dbus-accessibility-strict | File | 637 B | 0644 |
|
dbus-session | File | 638 B | 0644 |
|
dbus-session-strict | File | 919 B | 0644 |
|
dbus-strict | File | 677 B | 0644 |
|
dconf | File | 246 B | 0644 |
|
dovecot-common | File | 572 B | 0644 |
|
enchant | File | 1.96 KB | 0644 |
|
fcitx | File | 456 B | 0644 |
|
fcitx-strict | File | 712 B | 0644 |
|
fonts | File | 1.93 KB | 0644 |
|
freedesktop.org | File | 2.37 KB | 0644 |
|
gnome | File | 3.3 KB | 0644 |
|
gnupg | File | 356 B | 0644 |
|
ibus | File | 640 B | 0644 |
|
kde | File | 2.01 KB | 0644 |
|
kerberosclient | File | 1.08 KB | 0644 |
|
launchpad-integration | File | 824 B | 0644 |
|
ldapclient | File | 686 B | 0644 |
|
libpam-systemd | File | 659 B | 0644 |
|
likewise | File | 489 B | 0644 |
|
mdns | File | 436 B | 0644 |
|
mir | File | 593 B | 0644 |
|
mozc | File | 471 B | 0644 |
|
mysql | File | 641 B | 0644 |
|
nameservice | File | 3.75 KB | 0644 |
|
nis | File | 524 B | 0644 |
|
nvidia | File | 519 B | 0644 |
|
openssl | File | 470 B | 0644 |
|
orbit2 | File | 93 B | 0644 |
|
p11-kit | File | 899 B | 0644 |
|
perl | File | 872 B | 0644 |
|
php | File | 974 B | 0644 |
|
php5 | File | 105 B | 0644 |
|
postfix-common | File | 1.08 KB | 0644 |
|
private-files | File | 1.48 KB | 0644 |
|
private-files-strict | File | 1006 B | 0644 |
|
python | File | 1.5 KB | 0644 |
|
ruby | File | 906 B | 0644 |
|
samba | File | 834 B | 0644 |
|
smbpass | File | 476 B | 0644 |
|
ssl_certs | File | 924 B | 0644 |
|
ssl_keys | File | 650 B | 0644 |
|
svn-repositories | File | 1.61 KB | 0644 |
|
tor | File | 547 B | 0644 |
|
ubuntu-bittorrent-clients | File | 698 B | 0644 |
|
ubuntu-browsers | File | 1.62 KB | 0644 |
|
ubuntu-console-browsers | File | 611 B | 0644 |
|
ubuntu-console-email | File | 601 B | 0644 |
|
ubuntu-email | File | 902 B | 0644 |
|
ubuntu-feed-readers | File | 339 B | 0644 |
|
ubuntu-gnome-terminal | File | 182 B | 0644 |
|
ubuntu-helpers | File | 3.35 KB | 0644 |
|
ubuntu-konsole | File | 343 B | 0644 |
|
ubuntu-media-players | File | 2.18 KB | 0644 |
|
ubuntu-unity7-base | File | 2.39 KB | 0644 |
|
ubuntu-unity7-launcher | File | 191 B | 0644 |
|
ubuntu-unity7-messaging | File | 192 B | 0644 |
|
ubuntu-xterm | File | 237 B | 0644 |
|
user-download | File | 876 B | 0644 |
|
user-mail | File | 837 B | 0644 |
|
user-manpages | File | 889 B | 0644 |
|
user-tmp | File | 654 B | 0644 |
|
user-write | File | 864 B | 0644 |
|
video | File | 123 B | 0644 |
|
wayland | File | 580 B | 0644 |
|
web-data | File | 705 B | 0644 |
|
winbind | File | 739 B | 0644 |
|
wutmp | File | 585 B | 0644 |
|
xad | File | 883 B | 0644 |
|
xdg-desktop | File | 673 B | 0644 |
|