/usr/bin/swtpm rm,
- /tmp/** rwk,
- owner @{HOME}/** rwk,
- owner /var/lib/libvirt/swtpm/** rwk,
- /run/libvirt/qemu/swtpm/*.sock rwk,
- owner /var/log/swtpm/libvirt/qemu/*.log rwk,
- owner /run/libvirt/qemu/swtpm/*.pid rwk,
- owner /dev/vtpmx rw,
- owner /etc/nsswitch.conf r,
- owner /var/lib/swtpm/** rwk,
- owner /run/swtpm/sock rw,
+ # Proxmox VE allow to save states on many possible locations, so allow everything for now.
+ /** rwk,
}