diff --git a/apparmor.d/profiles-m-r/nmap b/apparmor.d/profiles-m-r/nmap index c1b56af9..8ffa088d 100644 --- a/apparmor.d/profiles-m-r/nmap +++ b/apparmor.d/profiles-m-r/nmap @@ -20,6 +20,8 @@ profile nmap @{exec_path} { network inet dgram, network inet6 dgram, + network inet stream, + network inet6 stream, network inet raw, network inet6 raw, network netlink raw, @@ -29,6 +31,14 @@ profile nmap @{exec_path} { owner @{PROC}/@{pid}/net/dev r, owner @{PROC}/@{pid}/net/if_inet6 r, + owner @{PROC}/@{pid}/net/route r, + owner @{PROC}/@{pid}/net/ipv6_route r, + + # unprivileged +# @{PROC}/@{pid}/net/dev r, +# @{PROC}/@{pid}/net/if_inet6 r, +# @{PROC}/@{pid}/net/route r, +# @{PROC}/@{pid}/net/ipv6_route r, /usr/share/nmap/** r,