From d6148c7b239f5c01dc378393f4d3673ad788fd5f Mon Sep 17 00:00:00 2001 From: nobodysu Date: Mon, 10 Jan 2022 21:49:01 +0000 Subject: [PATCH] Update grc - `mount` is too much, for now - expanding `ro` paths --- apparmor.d/profiles-g-l/grc | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/apparmor.d/profiles-g-l/grc b/apparmor.d/profiles-g-l/grc index 7fd83bbe..ab02bb6a 100644 --- a/apparmor.d/profiles-g-l/grc +++ b/apparmor.d/profiles-g-l/grc @@ -5,7 +5,7 @@ abi , include -@{GRC_PATHS_RO} = /etc @{HOME} /srv /tmp /var /usr/share /usr/lib/systemd +@{GRC_PATHS_RO} = /etc @{HOME} /srv /tmp /var /usr/{,local/}share /{,usr/}lib/systemd @{exec_path} = /{,usr/}bin/grc profile grc @{exec_path} { @@ -50,7 +50,6 @@ profile grc @{exec_path} { /{,usr/}bin/ip rPx, /{,usr/}bin/lsblk rPx, /{,usr/}bin/diff rPx, - /{,usr/}bin/mount rPx, /{,usr/}sbin/blkid rPx, /usr/{{bin,sbin}/traceroute,bin/linux-traceroute,bin/traceroute.db} rPx,