diff --git a/apparmor.d/groups/pacman/reflector b/apparmor.d/groups/pacman/reflector index 71a77d579..5e658e31d 100644 --- a/apparmor.d/groups/pacman/reflector +++ b/apparmor.d/groups/pacman/reflector @@ -14,6 +14,10 @@ profile reflector @{exec_path} flags=(attach_disconnected) { include include + capability net_admin, + capability dac_read_search, + capability dac_override, + network inet dgram, network inet6 dgram, network inet stream, @@ -33,5 +37,8 @@ profile reflector @{exec_path} flags=(attach_disconnected) { @{PROC}/cmdline r, @{PROC}/sys/kernel/osrelease r, + /dev/tty[0-9]* rw, + owner /dev/pts/[0-9]* rw, + include if exists }