# apparmor.d - Full set of apparmor profiles # Copyright (C) 2021-2024 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = @{bin}/systemd-tty-ask-password-agent profile systemd-tty-ask-password-agent @{exec_path} { include include include capability dac_override, capability net_admin, capability sys_resource, signal (receive) set=(term cont) peer=*//systemctl, signal (receive) set=(term cont) peer=default, signal (receive) set=(term cont) peer=logrotate, @{exec_path} mrix, @{run}/systemd/ask-password-block/{,*} rw, @{run}/systemd/ask-password/{,*} rw, @{run}/utmp rk, @{PROC}/@{pids}/stat r, @{sys}/devices/virtual/tty/console/active r, @{sys}/devices/virtual/tty/tty@{int}/active r, /dev/tty@{int} rw, include if exists } # vim:syntax=apparmor