# apparmor.d - Full set of apparmor profiles # Copyright (C) 2022-2024 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , include @{lib_dirs} = @{lib}/ /snap/{snapd,core}/@{int}@{lib} @{exec_path} = @{lib_dirs}/snapd/snap-discard-ns profile snap-discard-ns @{exec_path} { include capability setgid, capability sys_admin, network netlink raw, umount @{run}/snapd/ns/*.mnt, @{exec_path} mr, / r, @{run}/ r, @{run}/snapd/ r, @{run}/snapd/lock/ r, @{run}/snapd/lock/*.lock rwk, @{run}/snapd/ns/ r, @{run}/snapd/ns/* rw, include if exists } # vim:syntax=apparmor