# apparmor.d - Full set of apparmor profiles # Copyright (C) 2019-2022 Mikhail Morfikov # Copyright (C) 2021-2024 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = @{bin}/dmesg profile dmesg @{exec_path} { include include capability dac_read_search, capability syslog, @{exec_path} mr, @{sh_path} rix, @{bin}/less rPx -> child-pager, @{bin}/more rPx -> child-pager, @{bin}/pager rPx -> child-pager, /usr/share/terminfo/** r, owner @{PROC}/sys/kernel/pid_max r, /dev/kmsg r, deny @{bin}/{,*/} r, deny /{usr/,}local/{,s}bin/ r, deny /var/lib/flatpak/exports/bin/ r, deny @{HOME}/.go/bin/ r, deny @{user_bin_dirs}/ r, include if exists } # vim:syntax=apparmor