Skip to content

Instantly share code, notes, and snippets.

@dev-brutus
Last active August 29, 2015 14:20
Show Gist options
  • Save dev-brutus/30515ba368c9a57845f4 to your computer and use it in GitHub Desktop.
Save dev-brutus/30515ba368c9a57845f4 to your computer and use it in GitHub Desktop.
Apparmor for skype
# Last Modified: Sat May 2 15:06:08 2015
#include <tunables/global>
/usr/bin/skype {
#include <abstractions/audio>
#include <abstractions/base>
#include <abstractions/dbus>
#include <abstractions/fonts>
#include <abstractions/kde>
#include <abstractions/nameservice>
#include <abstractions/video>
dbus (send) bus=session path=/org/freedesktop/DBus interface=org.freedesktop.DBus,
dbus (send) bus=session path=/org/kde/statusnotifieritem/** interface=org.freedesktop.DBus,
dbus (send) bus=session path=/org/kde/statusnotifieritem/** interface=com.canonical.dbusmenu,
dbus (send) bus=session path=/org/kde/statusnotifieritem/** interface=org.kde.StatusNotifierItem,
dbus (send) bus=session path=/StatusNotifierWatcher,
dbus (receive) bus=session path=/org/kde/statusnotifieritem/** interface=org.freedesktop.DBus.Properties,
dbus (receive) bus=session path=/org/kde/statusnotifieritem/** interface=com.canonical.dbusmenu,
deny /home/*/.mozilla/ r,
/dev/ r,
/dev/* r,
/proc/*/net/dev r,
/dev/video* rw,
/etc/xdg/** rk,
/home/*/.ICEauthority r,
/home/*/.Skype/ rw,
/home/*/.Skype/** rwk,
/home/*/.Xauthority r,
/home/*/.config/Skype/** mrwk,
/home/*/.config/Trolltech.conf rk,
/home/*/.fontconfig/* r,
/home/*/skype-download/ rw,
/home/*/skype-download/** rwk,
/proc/*/fd r,
/proc/*/fd/ r,
/proc/*/net/arp r,
/proc/*/net/route r,
/proc/*/task r,
/proc/*/task/ r,
/proc/interrupts r,
/proc/sys/kernel/osrelease r,
/proc/sys/kernel/ostype r,
/sys/devices/system/cpu r,
/sys/devices/system/cpu/ r,
/sys/devices/system/cpu/** r,
/sys/devices/virtual/net/*/flags r,
/tmp/.ICE-unix/* w,
/tmp/.X11-unix/X0 w,
/usr/bin/gsettings Ux,
/usr/bin/pulseaudio Ux,
/usr/bin/skype mr,
/usr/bin/xdg-open Ux,
/usr/lib/qt4/plugins/iconengines/ r,
/usr/lib/qt4/plugins/imageformats/ r,
/usr/lib/qt4/plugins/imageformats/*.so mr,
/usr/lib/qt4/plugins/inputmethods/ r,
/usr/share/X11/locale/** r,
/usr/share/icons/** rk,
/usr/share/skype/** rk,
/var/cache/libx11/compose/* r,
/var/lib/dbus/machine-id r,
/{run,dev}/shm/pulse-shm* rwk,
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment