What about blocking access by default to directories that begin with . (like .config, .cache, etc.) ?
I think that might fix your KeePassX use case but still allow users to use their browser to upload pictures either from their Pictures/ directory or whatever named normal directory in their home directory. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1662501 Title: AppArmor profile for ubuntu-browsers allows too much read access To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1662501/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs