--- a/profiles/apparmor.d/usr.sbin.dnsmasq +++ b/profiles/apparmor.d/usr.sbin.dnsmasq @@ -18,6 +18,7 @@ profile dnsmasq /usr/{bin,sbin}/dnsmasq include include include + include capability chown, capability net_bind_service, @@ -38,6 +39,8 @@ profile dnsmasq /usr/{bin,sbin}/dnsmasq @{PROC}/@{pid}/fd/ r, + /tmp/** r, + /etc/dnsmasq.conf r, /etc/dnsmasq.d/ r, /etc/dnsmasq.d/* r,