# apparmor.d - Full set of apparmor profiles # Copyright (C) 2019-2021 Mikhail Morfikov # Copyright (C) 2023-2024 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = @{sbin}/parted profile parted @{exec_path} { include include capability sys_admin, capability sys_rawio, ptrace read, @{exec_path} mr, @{sh_path} rix, @{bin}/udevadm rCx -> udevadm, @{sbin}/dmidecode rPx, /etc/inputrc r, owner @{user_img_dirs}/{,**} rwk, @{PROC}/devices r, @{PROC}/swaps r, owner @{PROC}/@{pid}/mounts r, profile udevadm { include include include owner @{user_img_dirs}/{,**} rwk, include if exists } include if exists } # vim:syntax=apparmor