# apparmor.d - Full set of apparmor profiles # Copyright (C) 2018-2021 Mikhail Morfikov # Copyright (C) 2021-2024 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = @{bin}/usbguard-dbus profile usbguard-dbus @{exec_path} { include include # Needed? deny capability sys_nice, unix (send, receive, connect) type=stream peer=(label=usbguard-daemon, addr=@@{int}), @{exec_path} mr, /dev/shm/qb-usbguard-{request,response,event}-@{int}-@{int}-@{int}-{header,data} rw, /dev/shm/qb-@{int}-@{int}-@{int}-*/qb-{request,response,event}-usbguard-{header,data} rw, include if exists } # vim:syntax=apparmor