diff --git a/apparmor.d/groups/virt/cni-xtables-nft b/apparmor.d/groups/virt/cni-xtables-nft index 45d2820a..d562f044 100644 --- a/apparmor.d/groups/virt/cni-xtables-nft +++ b/apparmor.d/groups/virt/cni-xtables-nft @@ -7,7 +7,7 @@ abi , include @{exec_path} = /{usr/,}{s,}bin/xtables-nft-multi -profile cni-xtables-nft flags=(complain) { +profile cni-xtables-nft { include include diff --git a/apparmor.d/groups/virt/containerd-shim-runc-v2 b/apparmor.d/groups/virt/containerd-shim-runc-v2 index 81a19d24..ae091c99 100644 --- a/apparmor.d/groups/virt/containerd-shim-runc-v2 +++ b/apparmor.d/groups/virt/containerd-shim-runc-v2 @@ -8,7 +8,7 @@ abi , include @{exec_path} = /{usr/,}bin/containerd-shim-runc-v2 -profile containerd-shim-runc-v2 @{exec_path} flags=(complain,attach_disconnected) { +profile containerd-shim-runc-v2 @{exec_path} flags=(attach_disconnected) { include include diff --git a/apparmor.d/groups/virt/k3s b/apparmor.d/groups/virt/k3s index 0c661036..3f041cc4 100644 --- a/apparmor.d/groups/virt/k3s +++ b/apparmor.d/groups/virt/k3s @@ -7,7 +7,7 @@ abi , include @{exec_path} = /{usr/,}{local/,}bin/k3s -profile k3s @{exec_path} flags=(complain) { +profile k3s @{exec_path} { include include include diff --git a/apparmor.d/groups/virt/kubernetes-pause b/apparmor.d/groups/virt/kubernetes-pause index f38c949a..b621e63d 100644 --- a/apparmor.d/groups/virt/kubernetes-pause +++ b/apparmor.d/groups/virt/kubernetes-pause @@ -7,7 +7,7 @@ abi , include @{exec_path} = /pause -profile kubernetes-pause @{exec_path} flags=(complain,attach_disconnected) { +profile kubernetes-pause @{exec_path} flags=(attach_disconnected) { include signal (receive) set=kill, diff --git a/apparmor.d/profiles-s-z/zed b/apparmor.d/profiles-s-z/zed index 607feb10..a37053b9 100644 --- a/apparmor.d/profiles-s-z/zed +++ b/apparmor.d/profiles-s-z/zed @@ -7,7 +7,7 @@ abi , include @{exec_path} = /{usr/,}{local/,}{s,}bin/zed -profile zed @{exec_path} flags=(complain) { +profile zed @{exec_path} { include include diff --git a/apparmor.d/profiles-s-z/zfs b/apparmor.d/profiles-s-z/zfs index 4532b912..500cfec1 100644 --- a/apparmor.d/profiles-s-z/zfs +++ b/apparmor.d/profiles-s-z/zfs @@ -7,7 +7,7 @@ abi , include @{exec_path} = /{usr/,}{local/,}{s,}bin/zfs -profile zfs @{exec_path} flags=(complain) { +profile zfs @{exec_path} { include capability sys_admin, diff --git a/apparmor.d/profiles-s-z/zpool b/apparmor.d/profiles-s-z/zpool index e5ee8eec..8fb872dc 100644 --- a/apparmor.d/profiles-s-z/zpool +++ b/apparmor.d/profiles-s-z/zpool @@ -7,7 +7,7 @@ abi , include @{exec_path} = /{usr/,}{local/,}{s,}bin/zpool -profile zpool @{exec_path} flags=(complain) { +profile zpool @{exec_path} { include include