diff --git a/apparmor.d/profiles-s-z/update-secureboot-policy b/apparmor.d/profiles-s-z/update-secureboot-policy new file mode 100644 index 000000000..5ed5c8966 --- /dev/null +++ b/apparmor.d/profiles-s-z/update-secureboot-policy @@ -0,0 +1,17 @@ +# apparmor.d - Full set of apparmor profiles +# Copyright (C) 2022 Jeroen Rijken +# SPDX-License-Identifier: GPL-2.0-only + +abi , + +include + +@{exec_path} = /{usr/,}{,s}bin/update-secureboot-policy +profile update-secureboot-policy @{exec_path} flags=(complain) { + include + + @{exec_path} rm, + /usr/share/debconf/frontend rPx, + + include if exists +} \ No newline at end of file diff --git a/apparmor.d/profiles-s-z/whereis b/apparmor.d/profiles-s-z/whereis index b1f23b499..d55a83c0e 100644 --- a/apparmor.d/profiles-s-z/whereis +++ b/apparmor.d/profiles-s-z/whereis @@ -34,7 +34,6 @@ profile whereis @{exec_path} flags=(complain) { /snap/bin/ r, /var/lib/flatpak/exports/bin/ r, - owner @{HOME}/{.local/,}/{.,}bin/ r, owner @{HOME}/.krew/bin/ r, owner @{HOME}/{.,}go/bin/ r, owner @{HOME}/{.local/,}{.,}bin/ r,