# apparmor.d - Full set of apparmor profiles # Copyright (C) 2022 Jeroen Rijken # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = /{usr/,}{local/,}{s,}bin/zfs profile zfs @{exec_path} { include include capability sys_admin, capability dac_read_search, mount fstype=zfs, umount fstype=zfs, @{exec_path} mr, /etc/zfs/zfs-list.cache/{,*} rwk, # Sanoid generates temorary files with random names including underscores, directly under /tmp. # https://github.com/jimsalterjrs/sanoid/issues/758 /tmp/* rw, @{run}/zfs-list.cache@* rw, @{PROC}/@{pids}/mounts r, @{PROC}/sys/fs/pipe-max-size r, /dev/zfs rw, include if exists }