diff --git a/apparmor.d/profiles-s-z/spectre-meltdown-checker b/apparmor.d/profiles-s-z/spectre-meltdown-checker index 01e68b80..5ff0cce5 100644 --- a/apparmor.d/profiles-s-z/spectre-meltdown-checker +++ b/apparmor.d/profiles-s-z/spectre-meltdown-checker @@ -6,7 +6,7 @@ abi , include -@{exec_path} = /{usr/,}bin/spectre-meltdown-checker +@{exec_path} = /{,usr/}{,local/}bin/spectre-meltdown-checker{,.sh} profile spectre-meltdown-checker @{exec_path} { include @@ -77,7 +77,7 @@ profile spectre-meltdown-checker @{exec_path} { owner /tmp/intelfw-*/Intel-Linux-Processor-Microcode-Data-Files-master/** rw, owner @{HOME}/.mcedb rw, - owner /{usr/,}bin/spectre-meltdown-checker w, + owner @{exec_path} w, /tmp/ r, owner /tmp/{config,kernel}-* rw,