maybe chmod 0644 'apparmor.d/libvirt/TEMPLATE.qemu'
maybe chmod 0644 'apparmor.d/libvirt/libvirt-2a11cec6-cf27-414e-bb50-1fa264f07ff1'
maybe chmod 0644 'apparmor.d/libvirt/libvirt-2a11cec6-cf27-414e-bb50-1fa264f07ff1.files'
+maybe chmod 0644 'apparmor.d/libvirt/libvirt-865b0476-552c-48e0-8d91-a53104462e1e'
+maybe chmod 0644 'apparmor.d/libvirt/libvirt-865b0476-552c-48e0-8d91-a53104462e1e.files'
maybe chmod 0644 'apparmor.d/lightdm-guest-session'
maybe chmod 0755 'apparmor.d/local'
maybe chmod 0644 'apparmor.d/local/README'
--- /dev/null
+#
+# This profile is for the domain whose UUID matches this file.
+#
+
+#include <tunables/global>
+
+profile libvirt-865b0476-552c-48e0-8d91-a53104462e1e flags=(attach_disconnected) {
+ #include <abstractions/libvirt-qemu>
+ #include <libvirt/libvirt-865b0476-552c-48e0-8d91-a53104462e1e.files>
+
+}
--- /dev/null
+# DO NOT EDIT THIS FILE DIRECTLY. IT IS MANAGED BY LIBVIRT.
+ "/var/log/libvirt/**/win10.log" w,
+ "/var/lib/libvirt/qemu/domain-win10/monitor.sock" rw,
+ "/var/lib/libvirt/qemu/domain-3-win10/*" rw,
+ "/run/libvirt/**/win10.pid" rwk,
+ "/run/libvirt/**/*.tunnelmigrate.dest.win10" rw,
+ "/var/lib/libvirt/images/win10.qcow2" rwk,
+ "/var/lib/libvirt/images/virtio-win-0.1.173.iso" rk,
+ "/usr/share/OVMF/OVMF_CODE.secboot.fd" rk,
+ # don't audit writes to readonly files
+ deny "/usr/share/OVMF/OVMF_CODE.secboot.fd" w,
+ "/var/lib/libvirt/qemu/nvram/win10_VARS.fd" rwk,
+ "/dev/vhost-net" rw,
+ "/var/lib/libvirt/qemu/domain-3-win10/{,**}" rwk,
+ "/var/lib/libvirt/qemu/channel/target/domain-3-win10/{,**}" rwk,
+ "/var/lib/libvirt/qemu/domain-3-win10/master-key.aes" rwk,
+ "/dev/net/tun" rwk,