feat(profile): cleanup some rules already included in abs.

This commit is contained in:
Alexandre Pujol 2024-03-16 21:40:35 +00:00
parent b15aaae553
commit 0c5e71f971
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
36 changed files with 20 additions and 72 deletions

View file

@ -10,6 +10,7 @@ include <tunables/global>
profile aa-log @{exec_path} {
include <abstractions/base>
include <abstractions/consoles>
include <abstractions/nameservice-strict>
capability dac_read_search,
@ -18,8 +19,6 @@ profile aa-log @{exec_path} {
@{bin}/journalctl rix,
/etc/machine-id r,
/etc/nsswitch.conf r,
/etc/passwd r,
/var/lib/dbus/machine-id r,
/var/log/audit/* r,
@ -30,7 +29,6 @@ profile aa-log @{exec_path} {
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
@{PROC}/sys/kernel/random/boot_id r,
@{PROC}/sys/kernel/cap_last_cap r,
/dev/tty@{int} rw,