diff --git a/apparmor.d/groups/grub/grub-probe b/apparmor.d/groups/grub/grub-probe index 8b6195b46..3c22c2d27 100644 --- a/apparmor.d/groups/grub/grub-probe +++ b/apparmor.d/groups/grub/grub-probe @@ -34,6 +34,7 @@ profile grub-probe @{exec_path} { @{PROC}/devices r, /dev/**/ r, + /dev/mapper/control w, include if exists } diff --git a/apparmor.d/groups/snap/snap-update-ns b/apparmor.d/groups/snap/snap-update-ns index a7273d817..56b1cfc39 100644 --- a/apparmor.d/groups/snap/snap-update-ns +++ b/apparmor.d/groups/snap/snap-update-ns @@ -39,6 +39,9 @@ profile snap-update-ns @{exec_path} { / r, /tmp/ r, + /usr/ r, + /usr/local/ r, + /usr/local/share/ r, owner /snap/{,**} rw, diff --git a/apparmor.d/profiles-g-l/landscape-sysinfo b/apparmor.d/profiles-g-l/landscape-sysinfo index 78d0a9a9c..9a3629c7f 100644 --- a/apparmor.d/profiles-g-l/landscape-sysinfo +++ b/apparmor.d/profiles-g-l/landscape-sysinfo @@ -21,12 +21,15 @@ profile landscape-sysinfo @{exec_path} { network inet6 dgram, network netlink raw, - ptrace (read), + ptrace read, @{exec_path} mr, @{bin}/who rix, + @{lib}/@{python_name}/landscape/{,**/}__pycache__/ w, + @{lib}/@{python_name}/landscape/{,**/}__pycache__/**.pyc.@{u64} w, + /var/log/landscape/{,**} rw, @{run}/utmp rwk, diff --git a/apparmor.d/profiles-s-z/sysstat-sadc b/apparmor.d/profiles-s-z/sysstat-sadc index 982c48d81..e076f313c 100644 --- a/apparmor.d/profiles-s-z/sysstat-sadc +++ b/apparmor.d/profiles-s-z/sysstat-sadc @@ -21,10 +21,13 @@ profile sysstat-sadc @{exec_path} { /var/log/sysstat/{,**} rwk, @{sys}/bus/i2c/devices/ r, + @{sys}/class/fc_host/ r, @{sys}/class/hwmon/ r, @{sys}/class/i2c-adapter/ r, @{sys}/devices/@{pci}/i2c-@{int}/name r, @{sys}/devices/@{pci}/net/*/duplex r, + @{sys}/devices/**/net/*/duplex r, + @{sys}/devices/**/net/*/speed r, @{sys}/devices/virtual/net/*/duplex r, @{sys}/devices/virtual/net/*/speed r, diff --git a/apparmor.d/profiles-s-z/tlp b/apparmor.d/profiles-s-z/tlp index 6ccb111cd..ff447e81e 100644 --- a/apparmor.d/profiles-s-z/tlp +++ b/apparmor.d/profiles-s-z/tlp @@ -69,6 +69,7 @@ profile tlp @{exec_path} flags=(attach_disconnected) { @{run}/udev/data/+platform:* r, @{sys}/bus/pci/devices/ r, + @{sys}/class/drm/ r, @{sys}/class/net/ r, @{sys}/class/power_supply/ r, @{sys}/devices/@{pci}/ r,