parent
9728042f69
commit
debed741ca
1 changed files with 2 additions and 0 deletions
|
|
@ -24,6 +24,7 @@ profile sbctl @{exec_path} {
|
|||
/{boot,efi}/EFI/{,**} rw,
|
||||
/{boot,efi}/vmlinuz-linux* rw,
|
||||
@{lib}/fwupd/efi/{,**} rw,
|
||||
@{lib}/systemd/boot/efi/systemd-boot*.efi.signed rw,
|
||||
|
||||
@{sys}/firmware/efi/efivars/db-@{uuid} rw,
|
||||
@{sys}/firmware/efi/efivars/KEK-@{uuid} rw,
|
||||
|
|
@ -32,6 +33,7 @@ profile sbctl @{exec_path} {
|
|||
@{sys}/firmware/efi/efivars/SetupMode-@{uuid} r,
|
||||
|
||||
/dev/pts/@{int} rw,
|
||||
/dev/tpmrm@{int} rw,
|
||||
|
||||
# File Inherit
|
||||
deny network inet stream,
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue