diff --git a/apparmor.d/profiles-s-z/snapd-apparmor b/apparmor.d/profiles-s-z/snapd-apparmor new file mode 100644 index 00000000..b23ea4fd --- /dev/null +++ b/apparmor.d/profiles-s-z/snapd-apparmor @@ -0,0 +1,28 @@ +# apparmor.d - Full set of apparmor profiles +# Copyright (C) 2023 Alexandre Pujol +# SPDX-License-Identifier: GPL-2.0-only + +abi , + +include + +@{lib_dirs} = @{lib}/ /snap/snapd/@{int}@{lib} + +@{exec_path} = @{lib_dirs}/snapd/snapd-apparmor +profile snapd-apparmor @{exec_path} { + include + + @{exec_path} mrix, + + @{bin}/systemd-detect-virt rPx, + @{lib_dirs}/snapd/apparmor_parser rPx, + + @{lib_dirs}/snapd/info r, + + /var/lib/snapd/apparmor/profiles/ r, + + + @{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r, + + include if exists +} \ No newline at end of file diff --git a/dists/flags/main.flags b/dists/flags/main.flags index 09fa4eef..fd663b35 100644 --- a/dists/flags/main.flags +++ b/dists/flags/main.flags @@ -257,12 +257,16 @@ sddm attach_disconnected,mediate_deleted,complain sftp-server complain slirp4netns attach_disconnected,complain snap complain +snap-bootstrap complain snap-device-helper complain snap-discard-ns complain snap-failure complain +snap-repair complain snap-seccomp complain snap-update-ns complain snapd complain +snapd-apparmor complain +snapd-core-fixup complain spice-vdagent complain spice-vdagentd attach_disconnected,complain ssh complain