diff --git a/apparmor.d/profiles-g-l/kmod b/apparmor.d/profiles-g-l/kmod index 4cc9c3af6..f6dcec6e6 100644 --- a/apparmor.d/profiles-g-l/kmod +++ b/apparmor.d/profiles-g-l/kmod @@ -15,6 +15,7 @@ profile kmod @{exec_path} flags=(attach_disconnected) { include include + capability dac_read_search, capability dac_override, capability mknod, capability net_admin, @@ -70,6 +71,8 @@ profile kmod @{exec_path} flags=(attach_disconnected) { @{PROC}/cmdline r, @{PROC}/modules r, + /dev/tty@{int} rw, + deny /apparmor/.null rw, deny @{user_share_dirs}/gvfs-metadata/* r,