# apparmor.d - Full set of apparmor profiles # Copyright (C) 2019-2021 Mikhail Morfikov # Copyright (C) 2021-2024 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = @{bin}/unix_chkpwd profile unix-chkpwd @{exec_path} { include include include capability audit_write, network netlink raw, @{exec_path} mr, /etc/machine-id r, /etc/shadow r, # systemd userdb, used in nspawn @{run}/host/userdb/*.user r, @{run}/host/userdb/*.user-privileged r, owner /dev/tty@{int} rw, include if exists } # vim:syntax=apparmor