# apparmor.d - Full set of apparmor profiles # Copyright (C) 2020-2021 Mikhail Morfikov # Copyright (C) 2021-2024 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = @{bin}/check-bios-nx profile check-bios-nx @{exec_path} { include include # To remove the following errors: # /usr/sbin/check-bios-nx: 19: cannot create /dev/stderr: Permission denied capability dac_override, @{exec_path} r, @{sh_path} rix, @{bin}/uname rix, @{bin}/{,e}grep rix, @{bin}/getopt rix, @{bin}/kmod rCx -> kmod, @{bin}/rdmsr rPx, owner @{PROC}/@{pid}/fd/@{int} rw, profile kmod { include include @{lib}/modules/*/modules.* r, include if exists } include if exists } # vim:syntax=apparmor