# vim:syntax=apparmor # ------------------------------------------------------------------ # # Copyright (C) 2020-2021 Mikhail Morfikov # # This program is free software; you can redistribute it and/or # modify it under the terms of version 2 of the GNU General Public # License published by the Free Software Foundation. # # ------------------------------------------------------------------ abi , include @{exec_path} = /{usr/,}sbin/kvm-ok profile kvm-ok @{exec_path} { include @{exec_path} r, /{usr/,}bin/{,ba,da}sh rix, /{usr/,}bin/uname rix, /{usr/,}bin/{,e}grep rix, /{usr/,}bin/id rix, /{usr/,}bin/kmod rCx -> kmod, /{usr/,}sbin/rdmsr rPx, #/proc/cpuinfo r, #/dev/kvm r, #/dev/cpu/[0-9]*/msr r, # For shell pwd /root/ r, profile kmod { include /{usr/,}bin/kmod mr, /etc/modprobe.d/ r, /etc/modprobe.d/*.conf r, /{usr/,}lib/modprobe.d/ r, /{usr/,}lib/modprobe.d/*.conf r, @{PROC}/cmdline r, } include if exists }