apparmor/profiles/apparmor.d/iotop-c
Allen Huang 0c4f70d81b
profiles/iotop-c: remove owner, redundant rules
- Remove `owner` in /proc/ rules to enable non-root users
- add "include if exists" line to pass the pipeline
- change <abstractions/nameservice> to smaller <abstractions/nameservice-strict>

Signed-off-by: Allen Huang <allen.huang@canonical.com>
2025-02-07 13:40:14 +00:00

22 lines
446 B
Text

abi <abi/4.0>,
include <tunables/global>
profile iotop-c /usr/sbin/iotop-c {
include <abstractions/base>
include <abstractions/bash>
include <abstractions/nameservice-strict>
capability net_admin,
capability sys_admin,
/proc/*/cmdline r,
/proc/*/task/ r,
/usr/sbin/iotop-c mr,
/proc/ r,
/proc/sys/kernel/task_delayacct rw,
/proc/vmstat r,
owner @{HOME}/.config/iotop/iotoprc rw,
include if exists <local/iotop-c>
}