Also noted, the following IS in /etc/apparmor.d/usr.bin.freshclam
@{PROC}/filesystems r, owner @{PROC}/[0-9]*/status r,
And
$ ps -u clamav -f | more UID PID PPID C STIME TTY TIME CMD clamav 1348 1 0 08:38 ? 00:00:02 /usr/bin/freshclam -d --foregrou nd=true $ ls -l /proc/1348/status -r--r--r-- 1 root root 0 Jan 25 08:38 /proc/1348/status
Shows that root owns the status file, not the clamav user.
Also noted, the following IS in /etc/apparmor. d/usr.bin. freshclam
@{PROC}/filesystems r, /[0-9]* /status r,
owner @{PROC}
And
$ ps -u clamav -f | more
UID PID PPID C STIME TTY TIME CMD
clamav 1348 1 0 08:38 ? 00:00:02 /usr/bin/freshclam -d --foregrou
nd=true
$ ls -l /proc/1348/status
-r--r--r-- 1 root root 0 Jan 25 08:38 /proc/1348/status
Shows that root owns the status file, not the clamav user.