# apparmor.d - Full set of apparmor profiles # Copyright (C) 2021 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , include profile acpi-powerbtn flags=(attach_disconnected) { include /etc/acpi/powerbtn-acpi-support.sh r, /{usr/,}{s,}bin/killall5 rix, /{usr/,}{s,}bin/shutdown rix, /{usr/,}bin/{ba,da,}sh rix, /{usr/,}bin/{e,}grep rix, /{usr/,}bin/dbus-send rix, /{usr/,}bin/pgrep rix, /{usr/,}bin/pinky rix, /{usr/,}bin/sed rix, /etc/acpi/powerbtn.sh rix, /{usr/,}bin/systemctl rPx -> child-systemctl, /{usr/,}bin/ps rPx, /{usr/,}bin/fgconsole rCx, /usr/share/acpi-support/** r, @{PROC} r, @{PROC}/uptime r, @{PROC}/@{pids}/cmdline r, @{PROC}/@{pids}/stat r, deny / r, profile fgconsole { include capability sys_tty_config, /{usr/,}bin/fgconsole r, /dev/tty rw, owner /dev/tty[0-9]* rw, } include if exists }