diff --git a/apparmor.d/profiles-m-r/mount-zfs b/apparmor.d/profiles-m-r/mount-zfs new file mode 100644 index 00000000..00c7c193 --- /dev/null +++ b/apparmor.d/profiles-m-r/mount-zfs @@ -0,0 +1,35 @@ +# apparmor.d - Full set of apparmor profiles +# Copyright (C) 2022 Alexandre Pujol +# SPDX-License-Identifier: GPL-2.0-only + +abi , + +include + +@{exec_path} = /{usr/,}{s,}bin/mount.zfs +profile mount-zfs @{exec_path} flags=(complain) { + include + include + + capability sys_admin, # To mount anything. + + @{exec_path} mr, + + @{MOUNTDIRS}/ r, + @{MOUNTS}/ r, + @{MOUNTS}/*/ r, + + mount fstype=zfs -> @{MOUNTDIRS}/, + mount fstype=zfs -> @{MOUNTS}/, + mount fstype=zfs -> @{MOUNTS}/*/, + mount fstype=zfs -> /, + mount fstype=zfs -> /*/, + + umount @{MOUNTDIRS}/, + umount @{MOUNTS}/, + umount @{MOUNTS}/*/, + umount /, + umount /*/, + + include if exists +}