# apparmor.d - Full set of apparmor profiles # Copyright (C) 2022-2024 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , include @{lib_dirs} = @{lib}/ /snap/{snapd,core}/@{int}@{lib} @{exec_path} = @{lib_dirs}/snapd/snap-failure profile snap-failure @{exec_path} { include @{exec_path} mr, @{bin}/systemctl rCx -> systemctl, @{lib_dirs}/snapd/snapd rPx, /var/lib/snapd/sequence/snapd.json r, @{PROC}/cmdline r, profile systemctl { include include include if exists } include if exists } # vim:syntax=apparmor