# apparmor.d - Full set of apparmor profiles # Copyright (C) 2023-2024 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = @{bin}/aa-enforce @{bin}/aa-complain profile aa-enforce @{exec_path} { include include include capability dac_read_search, @{exec_path} mr, @{bin}/ r, @{bin}/apparmor_parser rPx, /usr/share/terminfo/** r, /etc/apparmor/logprof.conf r, /etc/apparmor.d/{,**} rw, @{etc_ro}/inputrc r, owner /snap/core@{int}/@{int}/etc/apparmor.d/{,**} rw, owner /var/lib/snapd/apparmor/{,**} rw, owner @{PROC}/@{pid}/fd r, include if exists } # vim:syntax=apparmor