we can have them as standard file (*most* of the time that would be
in /var/lib/vz or /mnt/pve/**), as LV/RBD in /dev or as zfs volume
anywhere, so basically we need to cut the profile in scope a lot and
allow write access in any place of the FS hierarchy for now (we plan
to have a mount namspace where we bind mount VM disk/state into in
the long term).
Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
/usr/bin/swtpm rm,
- /tmp/** rwk,
- owner @{HOME}/** rwk,
- owner /var/lib/libvirt/swtpm/** rwk,
- /run/libvirt/qemu/swtpm/*.sock rwk,
- owner /var/log/swtpm/libvirt/qemu/*.log rwk,
- owner /run/libvirt/qemu/swtpm/*.pid rwk,
- owner /dev/vtpmx rw,
- owner /etc/nsswitch.conf r,
- owner /var/lib/swtpm/** rwk,
- owner /run/swtpm/sock rw,
+ # Proxmox VE allow to save states on many possible locations, so allow everything for now.
+ /** rwk,
}