diff --git a/interfaces/builtin/fwupd.go b/interfaces/builtin/fwupd.go index 22453148a38..70f25942180 100644 --- a/interfaces/builtin/fwupd.go +++ b/interfaces/builtin/fwupd.go @@ -154,6 +154,10 @@ const fwupdPermanentSlotAppArmor = ` /sys/devices/**/psp_vbflash rw, /sys/devices/**/psp_vbflash_status r, + # Required by plugin thunderbolt + /sys/devices/**/nvm_non_active*/nvmem a, + /sys/devices/**/nvm_active*/nvmem r, + # DBus accesses #include dbus (send)