# apparmor.d - Full set of apparmor profiles # Copyright (C) 2019-2021 Mikhail Morfikov # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = /{usr/,}sbin/fsck profile fsck @{exec_path} { include include @{exec_path} mr, /{usr/,}sbin/e2fsck rPx, /{usr/,}sbin/fsck.* rPx, /etc/fstab r, @{PROC}/partitions r, owner @{PROC}/@{pid}/mountinfo r, owner @{run}/fsck/ rw, owner @{run}/fsck/*.lock rwk, # When a mount dir is passed to fsck as an argument. /media/*/ r, /boot/ r, /home/ r, owner @{run}/blkid/blkid.tab{,-*} rw, owner @{run}/blkid/blkid.tab.old rwl -> @{run}/blkid/blkid.tab, include if exists }