# vim:syntax=apparmor # ------------------------------------------------------------------ # # Copyright (C) 2019-2021 Mikhail Morfikov # # This program is free software; you can redistribute it and/or # modify it under the terms of version 2 of the GNU General Public # License published by the Free Software Foundation. # # ------------------------------------------------------------------ abi , include @{exec_path} = /{usr/,}sbin/fdisk profile fdisk @{exec_path} { include include # Needed to inform the system of newly created/removed partitions # ioctl(3, BLKRRPART) = -1 EACCES (Permission denied) capability sys_admin, # To remove the following errors: # kernel: device-mapper: core: fdisk: sending ioctl 5331 to DM device without required privilege. capability sys_rawio, @{exec_path} mr, @{PROC}/partitions r, /etc/terminal-colors.d/fdisk.disable r, # For disk images owner @{HOME}/**.{iso,img,bin,mdf,nrg} rwk, owner /media/*/**.{iso,img,bin,mdf,nrg} rwk, owner @{HOME}/**.{ISO,IMG,BIN,MDF,NRG} rwk, owner /media/*/**.{ISO,IMG,BIN,MDF,NRG} rwk, # For backups owner @{HOME}/**.{bak,back} rwk, owner /media/*/**.{bak,back} rwk, include if exists }