2018-09-30 14:17:30 +03:00
|
|
|
# vim:syntax=apparmor
|
|
|
|
|
2023-06-30 23:36:12 -07:00
|
|
|
abi <abi/4.0>,
|
2020-05-05 00:08:39 -07:00
|
|
|
|
2020-06-09 23:30:24 +02:00
|
|
|
include <tunables/global>
|
2018-09-30 14:17:30 +03:00
|
|
|
|
|
|
|
profile nvidia_modprobe {
|
2020-06-09 23:30:24 +02:00
|
|
|
include <abstractions/base>
|
2018-09-30 14:17:30 +03:00
|
|
|
|
|
|
|
# Capabilities
|
|
|
|
|
|
|
|
capability chown,
|
|
|
|
capability mknod,
|
|
|
|
capability setuid,
|
|
|
|
capability sys_admin,
|
|
|
|
|
|
|
|
# Main executable
|
|
|
|
|
|
|
|
/usr/bin/nvidia-modprobe mr,
|
|
|
|
|
|
|
|
# Other executables
|
|
|
|
|
|
|
|
/usr/bin/kmod Cx -> kmod,
|
|
|
|
|
|
|
|
# System files
|
|
|
|
|
2020-09-03 18:20:33 +03:00
|
|
|
/dev/nvidia-modeset w,
|
2018-09-30 14:17:30 +03:00
|
|
|
/dev/nvidia-uvm w,
|
|
|
|
/dev/nvidia-uvm-tools w,
|
2018-11-08 20:00:45 +02:00
|
|
|
@{sys}/bus/pci/devices/ r,
|
|
|
|
@{sys}/devices/pci[0-9]*/**/config r,
|
2018-09-30 14:17:30 +03:00
|
|
|
@{PROC}/devices r,
|
2020-08-30 19:24:29 +03:00
|
|
|
@{PROC}/driver/nvidia/params r,
|
2018-09-30 14:17:30 +03:00
|
|
|
@{PROC}/modules r,
|
|
|
|
@{PROC}/sys/kernel/modprobe r,
|
|
|
|
|
|
|
|
# Child profiles
|
|
|
|
|
|
|
|
profile kmod {
|
2020-06-09 23:30:24 +02:00
|
|
|
include <abstractions/base>
|
2018-09-30 14:17:30 +03:00
|
|
|
|
|
|
|
# Capabilities
|
|
|
|
|
|
|
|
capability sys_module,
|
|
|
|
|
|
|
|
# Main executable
|
|
|
|
|
|
|
|
/usr/bin/kmod mrix,
|
|
|
|
|
|
|
|
# Other executables
|
|
|
|
|
|
|
|
/{,usr/}bin/{,ba,da}sh ix,
|
|
|
|
|
|
|
|
# System files
|
|
|
|
|
|
|
|
/etc/modprobe.d/{,*.conf} r,
|
2023-02-11 19:42:58 +02:00
|
|
|
/etc/nvidia/{current,legacy*,tesla*}/*.conf r,
|
2018-11-08 20:00:45 +02:00
|
|
|
@{sys}/module/ipmi_devintf/initstate r,
|
|
|
|
@{sys}/module/ipmi_msghandler/initstate r,
|
2023-02-11 19:42:58 +02:00
|
|
|
@{sys}/module/{drm,nvidia}/initstate r,
|
2018-09-30 14:17:30 +03:00
|
|
|
@{PROC}/cmdline r,
|
|
|
|
}
|
|
|
|
|
|
|
|
# Site-specific additions and overrides. See local/README for details.
|
2020-04-28 22:25:27 +02:00
|
|
|
include if exists <local/nvidia_modprobe>
|
2018-09-30 14:17:30 +03:00
|
|
|
}
|
|
|
|
|