AppArmor prevent program from reading dirs/files I haven't explicitly allowed?

The name of the pictureThe name of the pictureThe name of the pictureClash Royale CLAN TAG#URR8PPP











up vote
0
down vote

favorite












I don't want programs to be able to read my whole home directory. For example, I'd like to have firefox's read ability restricted to:



owner @HOME/Downloads/ r,
owner @HOME/Downloads/** rwk,
owner @HOME/.mozilla/ r,
owner @HOME/.mozilla/** rwk,



  • plus all the appropriate dirs in .cache, .config etc

Thing about is that apparmor gives my user's reading rights, meaning ff can read everything unless I say



deny @HOME/Documents/ rwk,



Documents will be available for firefox.



Is there no way of denying the reading rights to everything in the home dir with the exceptions being the files I list in the profile?









share

























    up vote
    0
    down vote

    favorite












    I don't want programs to be able to read my whole home directory. For example, I'd like to have firefox's read ability restricted to:



    owner @HOME/Downloads/ r,
    owner @HOME/Downloads/** rwk,
    owner @HOME/.mozilla/ r,
    owner @HOME/.mozilla/** rwk,



    • plus all the appropriate dirs in .cache, .config etc

    Thing about is that apparmor gives my user's reading rights, meaning ff can read everything unless I say



    deny @HOME/Documents/ rwk,



    Documents will be available for firefox.



    Is there no way of denying the reading rights to everything in the home dir with the exceptions being the files I list in the profile?









    share























      up vote
      0
      down vote

      favorite









      up vote
      0
      down vote

      favorite











      I don't want programs to be able to read my whole home directory. For example, I'd like to have firefox's read ability restricted to:



      owner @HOME/Downloads/ r,
      owner @HOME/Downloads/** rwk,
      owner @HOME/.mozilla/ r,
      owner @HOME/.mozilla/** rwk,



      • plus all the appropriate dirs in .cache, .config etc

      Thing about is that apparmor gives my user's reading rights, meaning ff can read everything unless I say



      deny @HOME/Documents/ rwk,



      Documents will be available for firefox.



      Is there no way of denying the reading rights to everything in the home dir with the exceptions being the files I list in the profile?









      share













      I don't want programs to be able to read my whole home directory. For example, I'd like to have firefox's read ability restricted to:



      owner @HOME/Downloads/ r,
      owner @HOME/Downloads/** rwk,
      owner @HOME/.mozilla/ r,
      owner @HOME/.mozilla/** rwk,



      • plus all the appropriate dirs in .cache, .config etc

      Thing about is that apparmor gives my user's reading rights, meaning ff can read everything unless I say



      deny @HOME/Documents/ rwk,



      Documents will be available for firefox.



      Is there no way of denying the reading rights to everything in the home dir with the exceptions being the files I list in the profile?







      firefox profile apparmor





      share












      share










      share



      share










      asked 3 mins ago









      thebunnyrules

      387210




      387210

























          active

          oldest

          votes











          Your Answer








          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "106"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          convertImagesToLinks: false,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: null,
          bindNavPrevention: true,
          postfix: "",
          imageUploader:
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          ,
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );













           

          draft saved


          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f479526%2fapparmor-prevent-program-from-reading-dirs-files-i-havent-explicitly-allowed%23new-answer', 'question_page');

          );

          Post as a guest



































          active

          oldest

          votes













          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes















           

          draft saved


          draft discarded















































           


          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f479526%2fapparmor-prevent-program-from-reading-dirs-files-i-havent-explicitly-allowed%23new-answer', 'question_page');

          );

          Post as a guest













































































          Popular posts from this blog

          How to check contact read email or not when send email to Individual?

          Christian Cage

          How to properly install USB display driver for Fresco Logic FL2000DX on Ubuntu?