mirror of
https://gitlab.com/apparmor/apparmor
synced 2025-08-31 06:16:03 +00:00
profiles: allow sanitized_helper to run snap applications
This allows evince to share the document to a program running as a snap, e.g. mail via firefox. Given that /usr/bin/snap itself is not confined I chose to use ux, rather than pux. Tested locally on Ubuntu 24.04 by sharing a document from evince to firefox. Fixes: https://bugs.launchpad.net/apparmor/+bug/2095872 Jira: https://bugs.launchpad.net/apparmor/+bug/2095872 Signed-off-by: Zygmunt Krynicki <zygmunt.krynicki@canonical.com>
This commit is contained in:
@@ -83,6 +83,10 @@ profile sanitized_helper {
|
||||
/opt/brave.com/brave{,-beta,-dev,-nightly}/chrome_crashpad_handler Pixr,
|
||||
/opt/brave.com/brave{,-beta,-dev,-nightly}/{,**/}lib*.so{,.*} m,
|
||||
|
||||
# Allow running snap applications
|
||||
# https://bugs.launchpad.net/apparmor/+bug/2095872
|
||||
/usr/bin/snap ux,
|
||||
|
||||
# Full access
|
||||
/ r,
|
||||
/** rwkl,
|
||||
|
Reference in New Issue
Block a user