From 5059946c4fae73506c42e5e8dd7d1253117d7817 Mon Sep 17 00:00:00 2001 From: nobodysu Date: Tue, 30 Nov 2021 17:47:40 +0000 Subject: [PATCH] Update spectre-meltdown-checker --- apparmor.d/profiles-s-z/spectre-meltdown-checker | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/apparmor.d/profiles-s-z/spectre-meltdown-checker b/apparmor.d/profiles-s-z/spectre-meltdown-checker index 4a6c618a..506b3501 100644 --- a/apparmor.d/profiles-s-z/spectre-meltdown-checker +++ b/apparmor.d/profiles-s-z/spectre-meltdown-checker @@ -25,7 +25,7 @@ profile spectre-meltdown-checker @{exec_path} { /{usr/,}bin/cut rix, /{usr/,}bin/{,e}grep rix, /{usr/,}bin/head rix, - /{usr/,}bin/gawk rix, + /{usr/,}bin/{,g,m}awk rix, /{usr/,}bin/sed rix, /{usr/,}bin/od rix, /{usr/,}bin/dd rix, @@ -54,7 +54,9 @@ profile spectre-meltdown-checker @{exec_path} { /{usr/,}{s,}bin/iucode_tool rix, /{usr/,}bin/dmesg rix, /{usr/,}bin/mount rix, - + /{usr/,}bin/find rix, + /{usr/,}bin/xargs rix, + /{usr/,}bin/pgrep rCx -> pgrep, /{usr/,}bin/ccache rCx -> ccache, /{usr/,}bin/kmod rCx -> kmod, @@ -90,6 +92,7 @@ profile spectre-meltdown-checker @{exec_path} { @{PROC}/cmdline r, @{PROC}/kallsyms r, @{PROC}/modules r, + @{PROC}/@{pid}/status r, /var/lib/dbus/machine-id r, /etc/machine-id r,