]> Frank Brehm's Git Trees - config/bruni/etc-mint-new1.git/commitdiff
committing changes in /etc made by "/usr/bin/apt full-upgrade -y"
authorFrank Brehm <frank@brehm-online.com>
Sun, 14 May 2023 13:51:15 +0000 (15:51 +0200)
committerFrank Brehm <root@bruni.home.brehm-online.com>
Sun, 14 May 2023 13:51:15 +0000 (15:51 +0200)
Packages with configuration changes:
-swtpm 0.6.3-0ubuntu3 amd64
+swtpm 0.6.3-0ubuntu3.1 amd64

Package changes:
-swtpm 0.6.3-0ubuntu3 amd64
-swtpm-tools 0.6.3-0ubuntu3 amd64
+swtpm 0.6.3-0ubuntu3.1 amd64
+swtpm-tools 0.6.3-0ubuntu3.1 amd64

apparmor.d/usr.bin.swtpm

index 386137b352369517bdea3b653a23aa8ea99284d6..56702adbcdcbe397c552053ed8be6046e493fe80 100644 (file)
@@ -1,7 +1,7 @@
 # vim:syntax=apparmor
 # AppArmor policy for swtpm
 # Author: Lena Voytek <lena.voytek@canonical.com>
-# Last Modified: Fri Feb 18 10:23:53 2022
+# Last Modified: Tue Oct 11 10:53:05 2022
 
 #include <tunables/global>
 
@@ -12,7 +12,13 @@ profile swtpm /usr/bin/swtpm {
   # Site-specific additions and overrides. See local/README for details.
   #include <local/usr.bin.swtpm>
 
+  capability chown,
   capability dac_override,
+  capability dac_read_search,
+  capability fowner,
+  capability fsetid,
+  capability setgid,
+  capability setuid,
 
   network inet stream,
   network inet6 stream,
@@ -21,12 +27,14 @@ profile swtpm /usr/bin/swtpm {
 
   /usr/bin/swtpm rm,
 
-  owner /tmp/** rwk,
+  /tmp/** rwk,
+  owner @{HOME}/** rwk,
   owner /var/lib/libvirt/swtpm/** rwk,
   /run/libvirt/qemu/swtpm/*.sock rwk,
   owner /var/log/swtpm/libvirt/qemu/*.log rwk,
   owner /run/libvirt/qemu/swtpm/*.pid rwk,
   owner /dev/vtpmx rw,
+  owner /etc/nsswitch.conf r,
   owner /var/lib/swtpm/** rwk,
   owner /run/swtpm/sock rw,
 }