diff --git a/apparmor.d/groups/freedesktop/pulseaudio b/apparmor.d/groups/freedesktop/pulseaudio index 5509e1d19..2a8d08deb 100644 --- a/apparmor.d/groups/freedesktop/pulseaudio +++ b/apparmor.d/groups/freedesktop/pulseaudio @@ -45,7 +45,7 @@ profile pulseaudio @{exec_path} { bus=session path=/Client0/EntryGroup[0-9]* interface=org.freedesktop.Avahi.EntryGroup - member={StateChanged} + member=StateChanged peer=(name=org.freedesktop.Avahi), dbus (send) @@ -117,15 +117,15 @@ profile pulseaudio @{exec_path} { bus=system path=/ interface=org.freedesktop.Avahi.Server - member={StateChanged} + member=StateChanged peer=(name=org.freedesktop.Avahi), dbus (send) bus=system path=/ - interface=org.freedesktop.hostname[0-9]* - member={Get} - peer=(name=/org/freedesktop/hostname1[0-9]*, + interface=org.freedesktop.hostname[0-9] + member=Get + peer=(name=/org/freedesktop/hostname[0-9]), @{exec_path} mrix, diff --git a/apparmor.d/groups/virt/k3s b/apparmor.d/groups/virt/k3s index fa8e6bbeb..00b3a7263 100644 --- a/apparmor.d/groups/virt/k3s +++ b/apparmor.d/groups/virt/k3s @@ -17,8 +17,8 @@ profile k3s @{exec_path} flags=(complain) { capability kill, capability dac_override, capability dac_read_search, - capability fsetid - capability fowner + capability fsetid, + capability fowner, capability net_admin, capability syslog, capability sys_admin, diff --git a/apparmor.d/profiles-s-z/zpool b/apparmor.d/profiles-s-z/zpool index 0a35b2912..e5ee8eec2 100644 --- a/apparmor.d/profiles-s-z/zpool +++ b/apparmor.d/profiles-s-z/zpool @@ -25,8 +25,8 @@ profile zpool @{exec_path} flags=(complain) { @{run}/blkid/blkid.tab.old l, @{run}/blkid/blkid.tab-* rwl, - @{sys}/bus/pci/slots/ - @{sys}/bus/pci/slots/[0-9]*/address + @{sys}/bus/pci/slots/ r, + @{sys}/bus/pci/slots/[0-9]*/address r, @{PROC}/@{pids}/mounts r, @{PROC}/sys/kernel/spl/hostid r,