diff --git a/apparmor.d/groups/pacman/pacman-hook-depmod b/apparmor.d/groups/pacman/pacman-hook-depmod index aaa32a1e..b3dcb70a 100644 --- a/apparmor.d/groups/pacman/pacman-hook-depmod +++ b/apparmor.d/groups/pacman/pacman-hook-depmod @@ -13,6 +13,7 @@ profile pacman-hook-depmod @{exec_path} { @{exec_path} mr, /{usr/,}bin/bash rix, + /{usr/,}bin/kmod rPx, /{usr/,}bin/depmod rPx, # Inherit Silencer diff --git a/apparmor.d/groups/pacman/pacman-hook-dkms b/apparmor.d/groups/pacman/pacman-hook-dkms index 60bc88e6..8c7f0beb 100644 --- a/apparmor.d/groups/pacman/pacman-hook-dkms +++ b/apparmor.d/groups/pacman/pacman-hook-dkms @@ -14,8 +14,16 @@ profile pacman-hook-dkms @{exec_path} { @{exec_path} mr, + /{usr/,}bin/bash rix, /{usr/,}bin/kmod rPx, /{usr/,}bin/dkms rPx, + + /usr/src/ r, + /usr/src/**.conf r, + + /etc/dkms/{,*} r, + + /dev/tty rw, # Inherit Silencer deny network inet6 stream, diff --git a/apparmor.d/profiles-a-l/borg b/apparmor.d/profiles-a-l/borg index a4ab6256..de53e0a0 100644 --- a/apparmor.d/profiles-a-l/borg +++ b/apparmor.d/profiles-a-l/borg @@ -117,8 +117,8 @@ profile borg @{exec_path} { umount @{MOUNTS}/*/, umount @{MOUNTS}/*/*/, - - owner @{PROC}/@{pid}/mounts r, + + @{PROC}/@{pids}/mounts r, /dev/fuse rw, }