diff --git a/apparmor.d/groups/systemd/systemd-binfmt b/apparmor.d/groups/systemd/systemd-binfmt index 7cd0f96ca..405fdd9a3 100644 --- a/apparmor.d/groups/systemd/systemd-binfmt +++ b/apparmor.d/groups/systemd/systemd-binfmt @@ -30,6 +30,9 @@ profile systemd-binfmt @{exec_path} flags=(attach_disconnected) { @{PROC}/sys/kernel/osrelease r, owner @{PROC}/@{pid}/stat r, + /dev/tty@{int} rw, + /dev/pts/@{int} rw, + deny /apparmor/.null rw, include if exists