diff --git a/profiles/apparmor.d/ipa_verify b/profiles/apparmor.d/ipa_verify index 0b12f98da..1f03793e5 100644 --- a/profiles/apparmor.d/ipa_verify +++ b/profiles/apparmor.d/ipa_verify @@ -3,16 +3,12 @@ abi , include @{arg1}=/**/*.so -profile ipa_verify /usr/bin/ipa_verify flags=(unconfined) { - userns, - @{exec_path} mr, - profile ipa_verify /usr/bin/ipa_verify { include # Until we can replace arg1 above with real arg parsing include - /usr/bin/ipa_verify r, + @{exec_path} mr, # Probably enumerated by libcamera initialization but not needed for this tool's functionality deny /sys/devices/system/node/ r,