# apparmor.d - Full set of apparmor profiles # Copyright (C) 2023-2024 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = @{sbin}/multipath profile multipath @{exec_path} flags=(attach_disconnected) { include include capability sys_admin, capability sys_resource, unix (send, receive, connect) type=stream peer=(addr="@/org/kernel/linux/storage/multipathd"), @{exec_path} mr, /etc/multipath.conf r, /etc/multipath/ r, /etc/multipath/* rwk, /etc/systemd/system/ r, @{run}/systemd/system/ r, @{sys}/bus/ r, @{sys}/class/ r, @{sys}/module/*/parameters/multipath r, @{PROC}/devices r, @{PROC}/sys/fs/nr_open r, include if exists } # vim:syntax=apparmor