From 9ccda2a0a5831ffc8394792c47ed7df79e0f7be5 Mon Sep 17 00:00:00 2001 From: Alexandre Pujol Date: Tue, 14 Jun 2022 19:11:46 +0100 Subject: [PATCH] feat(profiles): initial version of mount.zfs --- apparmor.d/profiles-m-r/mount-zfs | 35 +++++++++++++++++++++++++++++++ 1 file changed, 35 insertions(+) create mode 100644 apparmor.d/profiles-m-r/mount-zfs diff --git a/apparmor.d/profiles-m-r/mount-zfs b/apparmor.d/profiles-m-r/mount-zfs new file mode 100644 index 00000000..00c7c193 --- /dev/null +++ b/apparmor.d/profiles-m-r/mount-zfs @@ -0,0 +1,35 @@ +# apparmor.d - Full set of apparmor profiles +# Copyright (C) 2022 Alexandre Pujol +# SPDX-License-Identifier: GPL-2.0-only + +abi , + +include + +@{exec_path} = /{usr/,}{s,}bin/mount.zfs +profile mount-zfs @{exec_path} flags=(complain) { + include + include + + capability sys_admin, # To mount anything. + + @{exec_path} mr, + + @{MOUNTDIRS}/ r, + @{MOUNTS}/ r, + @{MOUNTS}/*/ r, + + mount fstype=zfs -> @{MOUNTDIRS}/, + mount fstype=zfs -> @{MOUNTS}/, + mount fstype=zfs -> @{MOUNTS}/*/, + mount fstype=zfs -> /, + mount fstype=zfs -> /*/, + + umount @{MOUNTDIRS}/, + umount @{MOUNTS}/, + umount @{MOUNTS}/*/, + umount /, + umount /*/, + + include if exists +}