# apparmor.d - Full set of apparmor profiles # Copyright (C) 2020-2021 Mikhail Morfikov # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = /{usr/,}sbin/check-bios-nx profile check-bios-nx @{exec_path} { include include # To remove the following errors: # /usr/sbin/check-bios-nx: 19: cannot create /dev/stderr: Permission denied capability dac_override, @{exec_path} r, /{usr/,}bin/{,ba,da}sh rix, /{usr/,}bin/uname rix, /{usr/,}bin/{,e}grep rix, /{usr/,}bin/getopt rix, /{usr/,}bin/kmod rCx -> kmod, /{usr/,}sbin/rdmsr rPx, owner @{PROC}/@{pid}/fd/2 w, profile kmod { include /{usr/,}bin/kmod mr, /etc/modprobe.d/ r, /etc/modprobe.d/*.conf r, /{usr/,}lib/modprobe.d/ r, /{usr/,}lib/modprobe.d/*.conf r, /{usr/,}lib/modules/*/modules.* r, @{PROC}/cmdline r, } include if exists }