AppArmor: Grant read permission to mildenhall themes

This change works around reading mildenhall themes which is
installed in non-compliant path with the FHS[0]. When mildenhall
ships its themes files in the standard xdg data dirs, this change
should be reverted. See T4031.

[0]: default avatarSimon McVittie <>
Signed-off-by: default avatarJustin Kim <>
......@@ -90,4 +90,10 @@
# (for example themes) copied or bind-mounted into this location.
/var/lib/apertis_extensions/public/{,**} r,
# FIXME: The location of mildenhall themes should be moved to
# the standard xdg data dirs. If mildenhall installs its themes
# in the dirs, the following rule should be removed.
/var/lib/MILDENHALL_extensions/themes/{,**} r,
/etc/ssl/certs/ca-certificates.crt r,
