diff --git a/interfaces/apparmor/template.go b/interfaces/apparmor/template.go index 1c4be9420c2..8b045cecc91 100644 --- a/interfaces/apparmor/template.go +++ b/interfaces/apparmor/template.go @@ -369,6 +369,7 @@ var defaultTemplate = ` /sys/devices/virtual/tty/{console,tty*}/active r, /sys/fs/cgroup/memory/memory.limit_in_bytes r, /sys/fs/cgroup/memory/snap.@{SNAP_INSTANCE_NAME}{,.*}/memory.limit_in_bytes r, + /sys/kernel/mm/transparent_hugepage/hpage_pmd_size r, /sys/module/apparmor/parameters/enabled r, /{,usr/}lib/ r, @@ -714,6 +715,9 @@ profile snap-update-ns.###SNAP_INSTANCE_NAME### (attach_disconnected) { /dev/random r, /dev/urandom r, + # golang runtime variables + /sys/kernel/mm/transparent_hugepage/hpage_pmd_size r, + # Allow access to the uuidd daemon (this daemon is a thin wrapper around # time and getrandom()/{,u}random and, when available, runs under an # unprivilged, dedicated user).