# apparmor.d - Full set of apparmor profiles # Copyright (C) 2019-2021 Mikhail Morfikov # Copyright (C) 2021 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = /{usr/,}bin/umount profile umount @{exec_path} flags=(complain) { include include include capability chown, capability dac_read_search, capability setgid, capability setuid, capability sys_admin, umount, network inet stream, network inet6 stream, @{exec_path} mr, /{usr/,}sbin/umount.* rPx, /{usr/,}sbin/mount.* rPx, # Mount points @{HOME}/ r, @{HOME}/*/ r, @{HOME}/*/*/ r, @{HOME}/.cache/*/*/ r, @{MOUNTS}/*/ r, @{MOUNTS}/*/*/ r, /media/cdrom[0-9]/ r, /etc/mtab r, /etc/fstab r, owner @{PROC}/@{pid}/mountinfo r, @{sys}/devices/virtual/block/dm-[0-9]*/dm/name r, owner @{run}/mount/ rw, owner @{run}/mount/utab.lock wk, @{run}/mount/utab{,.*} rw, include if exists }