diff --git a/apparmor.d/profiles-m-r/mount b/apparmor.d/profiles-m-r/mount index e39cce5d..5d41be43 100644 --- a/apparmor.d/profiles-m-r/mount +++ b/apparmor.d/profiles-m-r/mount @@ -9,11 +9,12 @@ abi , include @{exec_path} = /{usr/,}{s,}bin/mount -profile mount @{exec_path} { +profile mount @{exec_path} flags=(attach_disconnected) { include include include include + include capability chown, capability dac_read_search,