From 8be553c6649ebafc28665cb5912b788b650924f1 Mon Sep 17 00:00:00 2001 From: Alexandre Pujol Date: Thu, 13 Mar 2025 18:51:43 +0100 Subject: [PATCH] feat(profile): add profile for simple-scan --- apparmor.d/profiles-s-z/simple-scan | 45 +++++++++++++++++++++++++++++ 1 file changed, 45 insertions(+) create mode 100644 apparmor.d/profiles-s-z/simple-scan diff --git a/apparmor.d/profiles-s-z/simple-scan b/apparmor.d/profiles-s-z/simple-scan new file mode 100644 index 000000000..f79b284fb --- /dev/null +++ b/apparmor.d/profiles-s-z/simple-scan @@ -0,0 +1,45 @@ +# apparmor.d - Full set of apparmor profiles +# Copyright (C) 2024 Alexandre Pujol +# SPDX-License-Identifier: GPL-2.0-only + +abi , + +include + +@{exec_path} = @{bin}/simple-scan +profile simple-scan @{exec_path} { + include + include + include + include + include + include + + network inet dgram, + network inet6 dgram, + network netlink raw, + + @{exec_path} mr, + + @{open_path} rPx -> child-open-help, + + /usr/share/snmp/{,**} r, + + /etc/sane.d/{,**} r, + + @{sys}/bus/scsi/devices/ r, + @{sys}/devices/virtual/dmi/id/board_name r, + @{sys}/devices/virtual/dmi/id/board_vendor r, + @{sys}/devices/virtual/dmi/id/board_version r, + @{sys}/devices/virtual/dmi/id/product_name r, + @{sys}/devices/virtual/dmi/id/product_version r, + @{sys}/devices/virtual/dmi/id/sys_vendor r, + + @{PROC}/scsi/scsi r, + + /dev/video@{int} rw, + + include if exists +} + +# vim:syntax=apparmor