# apparmor.d - Full set of apparmor profiles # Copyright (C) 2022 Jeroen Rijken # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = /{usr/,}{local/,}{s,}bin/zfs profile zfs @{exec_path} flags=(complain) { include capability sys_admin, @{exec_path} mr, /etc/zfs/zfs-list.cache/{,*} rwk, @{PROC}/@{pids}/mounts r, @{run}/zfs-list.cache@* rw, /dev/zfs rw, include if exists }