Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
profiles: loupe: harden and disable apparmor
The profile currently does not include disable-common nor makes `${HOME}` read-only, so the program can simply write to ~/.bashrc directly[1]. disable-common.inc was commented due to it apparently breaking bwrap. As discovered by @glitsj16, it seems that allowing the bwrap binary is enough to make it work (and that apparmor breaks loupe)[2]. So disable apparmor, allow bwrap and include disable-common.inc, plus other hardening by @glitsj16. This amends commit 9a0db13 ("profiles: add loupe", 2024-04-30) / PR #6327. [1] #6327 (review) [2] #6333 (comment)
- Loading branch information