#include profile frigate-rknpu-old flags=(attach_disconnected,mediate_deleted) { #include capability, file, signal, mount, umount, remount, network udp, network tcp, network dgram, network stream, network inet, network inet6, network netlink raw, network unix dgram, network, signal (send) set=(kill,term,int,hup,cont), capability net_admin, capability net_bind_service, capability dac_read_search, capability dac_override, capability chown, capability setgid, capability setuid, capability sys_admin, capability dac_read_search, # capability dac_override, # capability sys_rawio, # S6-Overlay /init ix, /run/{s6,s6-rc*,service}/** ix, /package/** ix, /command/** ix, /run/{,**} rwk, /dev/tty rw, /bin/** ix, /usr/bin/** ix, /usr/lib/bashio/** ix, /etc/s6/** rix, /run/s6/** rix, /etc/services.d/** rwix, /etc/cont-init.d/** rwix, /etc/cont-finish.d/** rwix, /init rix, /var/run/** mrwkl, /var/run/ mrwkl, /dev/i2c-1 mrwkl, # Files required /dev/fuse mrwkl, /dev/sda1 mrwkl, /dev/sdb1 mrwkl, /dev/nvme0 mrwkl, /dev/nvme1 mrwkl, /dev/mmcblk0p1 mrwkl, /dev/* mrwkl, /tmp/** mrkwl, /dev/shm/** rwix, # Data access /data/** rw, # suppress ptrace denials when using 'docker ps' or using 'ps' inside a container ptrace (trace,read) peer=docker-default, # docker daemon confinement requires explict allow rule for signal signal (receive) set=(kill,term) peer=/usr/bin/docker, }