-
Hi. I want to use this set of profiles, but I don't like the policy that programs have access to document directories by default. An example of a document directory is |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 2 replies
-
Yes, the concerned profiles are the one using any of However, some profiles do not use these abstractions (these abs are quite large as you said). The user access is usually directly coded in the profile. For example, see vlc and yacreader: apparmor.d/apparmor.d/profiles-s-z/vlc Lines 51 to 54 in adccd00 apparmor.d/apparmor.d/profiles-s-z/YACReaderLibrary Lines 32 to 33 in adccd00 Finally, some programs (file browsers, search engine) need full access to user data ( |
Beta Was this translation helpful? Give feedback.
Yes, the concerned profiles are the one using any of
abstractions/user-read
,abstractions/user-read-strict
,abstractions/user-write
,abstractions/user-write-strict
. Therefore you can edit these abstractions file to disable their effects.However, some profiles do not use these abstractions (these abs are quite large as you said). The user access is usually directly coded in the profile. For example, see vlc and yacreader:
apparmor.d/apparmor.d/profiles-s-z/vlc
Lines 51 to 54 in adccd00
apparmor.d/apparmor.d/p…