deny /sys/fs/cgroup?*{,/**} wklx,
deny /sys/fs?*{,/**} wklx,
-@BEGIN_APPARMOR_3@
include if exists <abstractions/libvirt-lxc.d>
-@END_APPARMOR_3@
/usr/{lib,lib64}/libswtpm_libtpms.so mr,
/usr/lib/@{multiarch}/libswtpm_libtpms.so mr,
-@BEGIN_APPARMOR_3@
# support for passt network back-end
/usr/bin/passt Cx -> passt,
include if exists <abstractions/passt>
}
-@END_APPARMOR_3@
# for save and resume
/{usr/,}bin/dash rmix,
owner /var/lib/libvirt/qemu/nvram/*_VARS.fd rwk,
owner /var/lib/libvirt/qemu/nvram/*_VARS.ms.fd rwk,
-@BEGIN_APPARMOR_3@
include if exists <abstractions/libvirt-qemu.d>
-@END_APPARMOR_3@
/**.[iI][sS][oO] r,
/**/disk{,.*} r,
-@BEGIN_APPARMOR_3@
include if exists <local/usr.lib.libvirt.virt-aa-helper>
-@END_APPARMOR_3@
-@BEGIN_APPARMOR_2@
- #include <local/usr.lib.libvirt.virt-aa-helper>
-@END_APPARMOR_2@
}
/usr/{lib,lib64,lib/qemu,libexec,libexec/qemu}/qemu-bridge-helper rmix,
}
-@BEGIN_APPARMOR_3@
include if exists <local/usr.sbin.libvirtd>
-@END_APPARMOR_3@
}
/usr/{lib,lib64,lib/qemu,libexec,libexec/qemu}/qemu-bridge-helper rmix,
}
-@BEGIN_APPARMOR_3@
include if exists <local/usr.sbin.virtqemud>
-@END_APPARMOR_3@
}
/etc/libvirt/hooks/** rmix,
/etc/xen/scripts/** rmix,
-@BEGIN_APPARMOR_3@
include if exists <local/usr.sbin.virtxend>
-@END_APPARMOR_3@
}