diff --git a/scrutiny/apparmor.txt b/scrutiny/apparmor.txt index 6874ca96d..11342f9ae 100644 --- a/scrutiny/apparmor.txt +++ b/scrutiny/apparmor.txt @@ -1,6 +1,6 @@ #include -profile scrutiny_addon flags=(attach_disconnected,mediate_deleted) { +profile 6c45555e_qbittorrent2 flags=(attach_disconnected,mediate_deleted) { #include capability, @@ -12,30 +12,27 @@ profile scrutiny_addon flags=(attach_disconnected,mediate_deleted) { capability setgid, capability setuid, capability dac_override, + capability sys_amin, + capability dac_read_search, # S6-Overlay /bin/** ix, /usr/bin/** ix, /usr/lib/bashio/** ix, - /etc/s6/** rix, - /run/s6/** rix, + /etc/s6/** ix, + /run/s6/** ix, /etc/services.d/** rwix, /etc/cont-init.d/** rwix, - /etc/cont-finish.d/** rwix, - /init rix, - /var/run/** mrwkl, - /var/run/ mrwkl, - /proc/self/attr/** mrwkl, + /etc/cont-finish.d/** rwix, # Files required /dev/sda1 mrwkl, /dev/sdb1 mrwkl, - /dev/mmcblk0p1 mrwkl, + /dev/mmcblk0p1 mrwkl, /dev/* mrwkl, /tmp/** mrkwl, # Data access - /data/** rw, - + /data/** rw, # suppress ptrace denials when using 'docker ps' or using 'ps' inside a container ptrace (trace,read) peer=docker-default,