From f8a3fae4f51f5f0caae6bed4c3de28ee2530a1ec Mon Sep 17 00:00:00 2001 From: Sebastian Weyer Date: Thu, 3 Oct 2024 07:03:11 +0200 Subject: [PATCH] Use * wildcard for nvgpu/igpu node apparmor profiles Instead of just granting apparmor permissions to igpu 0 to 9, use a wildcard to grant permissions going beyond 9. Signed-off-by: Sebastian Weyer --- interfaces/builtin/opengl.go | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/interfaces/builtin/opengl.go b/interfaces/builtin/opengl.go index 70d603c5818..71aecbbd0d2 100644 --- a/interfaces/builtin/opengl.go +++ b/interfaces/builtin/opengl.go @@ -189,9 +189,9 @@ unix (bind,listen) type=seqpacket addr="@cuda-uvmfd-[0-9a-f]*", /run/nvidia-xdriver-* rw, unix (send, receive) type=dgram peer=(addr="@var/run/nvidia-xdriver-*"), -/dev/nvgpu/igpu[0-9]/power rw, -/dev/nvgpu/igpu[0-9]/ctrl rw, -/dev/nvgpu/igpu[0-9]/prof rw, +/dev/nvgpu/igpu[0-9]*/power rw, +/dev/nvgpu/igpu[0-9]*/ctrl rw, +/dev/nvgpu/igpu[0-9]*/prof rw, /dev/host1x-fence rw, `