]> git.proxmox.com Git - swtpm.git/blobdiff - debian/usr.bin.swtpm
apparmor profile: adapt state file locations PVE supports
[swtpm.git] / debian / usr.bin.swtpm
index 44835127193bc683995fa13911393d53faa1259c..7f9618f1152daa7479915e9e623455c638daadc4 100644 (file)
@@ -25,14 +25,6 @@ profile swtpm /usr/bin/swtpm {
 
   /usr/bin/swtpm rm,
 
-  /tmp/** rwk,
-  owner @{HOME}/** rwk,
-  owner /var/lib/libvirt/swtpm/** rwk,
-  /run/libvirt/qemu/swtpm/*.sock rwk,
-  owner /var/log/swtpm/libvirt/qemu/*.log rwk,
-  owner /run/libvirt/qemu/swtpm/*.pid rwk,
-  owner /dev/vtpmx rw,
-  owner /etc/nsswitch.conf r,
-  owner /var/lib/swtpm/** rwk,
-  owner /run/swtpm/sock rw,
+  # Proxmox VE allow to save states on many possible locations, so allow everything for now.
+  /** rwk,
 }