diff --git a/apparmor.d/groups/snap/snap-discard-ns b/apparmor.d/groups/snap/snap-discard-ns index f1f6f9d67..38396f3eb 100644 --- a/apparmor.d/groups/snap/snap-discard-ns +++ b/apparmor.d/groups/snap/snap-discard-ns @@ -20,6 +20,7 @@ profile snap-discard-ns @{exec_path} { umount @{run}/snapd/ns/*.mnt, @{exec_path} mr, + @{lib_dirs}/**.so* mr, / r, @{run}/ r, diff --git a/apparmor.d/groups/snap/snap-failure b/apparmor.d/groups/snap/snap-failure index a4f89f558..edc9845e8 100644 --- a/apparmor.d/groups/snap/snap-failure +++ b/apparmor.d/groups/snap/snap-failure @@ -13,6 +13,7 @@ profile snap-failure @{exec_path} { include @{exec_path} mr, + @{lib_dirs}/**.so* mr, @{bin}/systemctl rCx -> systemctl, @{lib_dirs}/snapd/snapd rPx, diff --git a/apparmor.d/groups/snap/snap-seccomp b/apparmor.d/groups/snap/snap-seccomp index e7660f7b8..7857bcc6a 100644 --- a/apparmor.d/groups/snap/snap-seccomp +++ b/apparmor.d/groups/snap/snap-seccomp @@ -19,7 +19,6 @@ profile snap-seccomp @{exec_path} { network netlink raw, @{exec_path} mr, - @{lib_dirs}/**.so* mr, @{bin}/getent rix, diff --git a/apparmor.d/groups/snap/snap-update-ns b/apparmor.d/groups/snap/snap-update-ns index 3ce5bfdd4..3da082eef 100644 --- a/apparmor.d/groups/snap/snap-update-ns +++ b/apparmor.d/groups/snap/snap-update-ns @@ -30,6 +30,7 @@ profile snap-update-ns @{exec_path} { umount /usr/share/xml/iso-codes/, @{exec_path} mr, + @{lib_dirs}/**.so* mr, @{lib}/@{multiarch}/webkit2gtk-@{version}/ w, /usr/share/xml/iso-codes/ w, diff --git a/apparmor.d/groups/snap/snapd-aa-prompt-listener b/apparmor.d/groups/snap/snapd-aa-prompt-listener index 5620fc975..7b9adced7 100644 --- a/apparmor.d/groups/snap/snapd-aa-prompt-listener +++ b/apparmor.d/groups/snap/snapd-aa-prompt-listener @@ -13,6 +13,7 @@ profile snapd-aa-prompt-listener @{exec_path} { include @{exec_path} mrix, + @{lib_dirs}/**.so* mr, @{lib_dirs}/snapd/info r, diff --git a/apparmor.d/groups/snap/snapd-aa-prompt-ui b/apparmor.d/groups/snap/snapd-aa-prompt-ui index 14354cfb9..0d26f42d3 100644 --- a/apparmor.d/groups/snap/snapd-aa-prompt-ui +++ b/apparmor.d/groups/snap/snapd-aa-prompt-ui @@ -13,6 +13,7 @@ profile snapd-aa-prompt-ui @{exec_path} { include @{exec_path} mrix, + @{lib_dirs}/**.so* mr, @{lib_dirs}/snapd/info r,