diff --git a/apparmor.d/groups/pacman/mkinitcpio b/apparmor.d/groups/pacman/mkinitcpio index dcf5b10f..ed91f6c9 100644 --- a/apparmor.d/groups/pacman/mkinitcpio +++ b/apparmor.d/groups/pacman/mkinitcpio @@ -83,10 +83,10 @@ profile mkinitcpio @{exec_path} flags=(attach_disconnected) { # Manage /boot / r, - /{boot,efi}/ r, + /boot/ r, /{boot,efi}/EFI/{,**} rw, - /{boot,efi}/initramfs-*.img* rw, - /{boot,efi}/vmlinuz-* r, + /boot/initramfs-*.img* rw, + /boot/vmlinuz-* r, /usr/share/systemd/bootctl/** r, diff --git a/apparmor.d/groups/pacman/pacman b/apparmor.d/groups/pacman/pacman index 1c7015b1..8215e3f6 100644 --- a/apparmor.d/groups/pacman/pacman +++ b/apparmor.d/groups/pacman/pacman @@ -39,7 +39,7 @@ profile pacman @{exec_path} flags=(attach_disconnected) { ptrace read, - signal send set=usr1 peer=gvfsd, + signal send, signal receive set=winch peer=makepkg//sudo, @{exec_path} mrix, diff --git a/apparmor.d/groups/pacman/pacman-hook-mkinitcpio b/apparmor.d/groups/pacman/pacman-hook-mkinitcpio index 9ee488fb..a9bf4036 100644 --- a/apparmor.d/groups/pacman/pacman-hook-mkinitcpio +++ b/apparmor.d/groups/pacman/pacman-hook-mkinitcpio @@ -37,7 +37,7 @@ profile pacman-hook-mkinitcpio @{exec_path} flags=(attach_disconnected) { / r, /boot/ r, - /boot/efi/boot/boot*.efi rw, + /{boot,efi}/EFI/boot/boot*.efi rw, /boot/initramfs-*-fallback.img rw, /boot/initramfs-*.img rw, /boot/vmlinuz-* rw,