# apparmor.d - Full set of apparmor profiles # Copyright (C) 2022-2024 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = @{lib}/systemd/systemd-cryptsetup profile systemd-cryptsetup @{exec_path} { include include include include capability ipc_lock, capability net_admin, capability sys_admin, @{exec_path} mr, /etc/fstab r, @{run}/ r, @{run}/cryptsetup/ r, @{run}/cryptsetup/* rwk, @{run}/systemd/ask-password/* rw, @{sys}/devices/virtual/bdi/*/read_ahead_kb r, @{sys}/fs/ r, @{PROC}/devices r, owner @{PROC}/@{pid}/mountinfo r, include if exists }