From a4ba26133fcb8984fbe4cbd24e34d83907757d4e Mon Sep 17 00:00:00 2001 From: Alexandre Pujol Date: Sun, 12 Sep 2021 20:47:14 +0100 Subject: [PATCH] Update profiles. --- apparmor.d/groups/pacman/pacman-hook-depmod | 1 + apparmor.d/groups/pacman/pacman-hook-dkms | 8 ++++++++ apparmor.d/profiles-a-l/borg | 4 ++-- 3 files changed, 11 insertions(+), 2 deletions(-) diff --git a/apparmor.d/groups/pacman/pacman-hook-depmod b/apparmor.d/groups/pacman/pacman-hook-depmod index aaa32a1e..b3dcb70a 100644 --- a/apparmor.d/groups/pacman/pacman-hook-depmod +++ b/apparmor.d/groups/pacman/pacman-hook-depmod @@ -13,6 +13,7 @@ profile pacman-hook-depmod @{exec_path} { @{exec_path} mr, /{usr/,}bin/bash rix, + /{usr/,}bin/kmod rPx, /{usr/,}bin/depmod rPx, # Inherit Silencer diff --git a/apparmor.d/groups/pacman/pacman-hook-dkms b/apparmor.d/groups/pacman/pacman-hook-dkms index 60bc88e6..8c7f0beb 100644 --- a/apparmor.d/groups/pacman/pacman-hook-dkms +++ b/apparmor.d/groups/pacman/pacman-hook-dkms @@ -14,8 +14,16 @@ profile pacman-hook-dkms @{exec_path} { @{exec_path} mr, + /{usr/,}bin/bash rix, /{usr/,}bin/kmod rPx, /{usr/,}bin/dkms rPx, + + /usr/src/ r, + /usr/src/**.conf r, + + /etc/dkms/{,*} r, + + /dev/tty rw, # Inherit Silencer deny network inet6 stream, diff --git a/apparmor.d/profiles-a-l/borg b/apparmor.d/profiles-a-l/borg index a4ab6256..de53e0a0 100644 --- a/apparmor.d/profiles-a-l/borg +++ b/apparmor.d/profiles-a-l/borg @@ -117,8 +117,8 @@ profile borg @{exec_path} { umount @{MOUNTS}/*/, umount @{MOUNTS}/*/*/, - - owner @{PROC}/@{pid}/mounts r, + + @{PROC}/@{pids}/mounts r, /dev/fuse rw, }