# apparmor.d - Full set of apparmor profiles # Copyright (C) 2019-2021 Mikhail Morfikov # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = /{usr/,}sbin/gdisk profile gdisk @{exec_path} { include include # Needed to inform the system of newly created/removed partitions # ioctl(3, BLKRRPART) = -1 EACCES (Permission denied) # # Warning: The kernel is still using the old partition table. # The new table will be used at the next reboot or after you # run partprobe(8) or kpartx(8) # The operation has completed successfully. capability sys_admin, @{exec_path} mr, # For disk images owner @{HOME}/**.{iso,img,bin,mdf,nrg} rwk, owner /media/*/**.{iso,img,bin,mdf,nrg} rwk, owner @{HOME}/**.{ISO,IMG,BIN,MDF,NRG} rwk, owner /media/*/**.{ISO,IMG,BIN,MDF,NRG} rwk, # For backups owner @{HOME}/**.{bak,back} rwk, owner /media/*/**.{bak,back} rwk, include if exists }