fix(profile): various fixes from issue raised by the CI.
This commit is contained in:
parent
d4210c99d1
commit
1dace30af3
7 changed files with 18 additions and 1 deletions
|
|
@ -11,6 +11,8 @@ profile dpkg-script-systemd @{exec_path} {
|
||||||
include <abstractions/base>
|
include <abstractions/base>
|
||||||
include <abstractions/common/debconf>
|
include <abstractions/common/debconf>
|
||||||
|
|
||||||
|
capability dac_read_search,
|
||||||
|
|
||||||
@{exec_path} mrix,
|
@{exec_path} mrix,
|
||||||
|
|
||||||
@{coreutils_path} rix,
|
@{coreutils_path} rix,
|
||||||
|
|
@ -21,7 +23,7 @@ profile dpkg-script-systemd @{exec_path} {
|
||||||
@{bin}/dpkg-divert Px,
|
@{bin}/dpkg-divert Px,
|
||||||
@{bin}/dpkg-maintscript-helper Px,
|
@{bin}/dpkg-maintscript-helper Px,
|
||||||
@{bin}/journalctl Px,
|
@{bin}/journalctl Px,
|
||||||
@{bin}/kernel-install Px,
|
@{bin}/kernel-install mrPx,
|
||||||
@{bin}/systemctl Cx -> systemctl,
|
@{bin}/systemctl Cx -> systemctl,
|
||||||
@{bin}/systemd-machine-id-setup Px,
|
@{bin}/systemd-machine-id-setup Px,
|
||||||
@{bin}/systemd-sysusers Px,
|
@{bin}/systemd-sysusers Px,
|
||||||
|
|
@ -35,11 +37,14 @@ profile dpkg-script-systemd @{exec_path} {
|
||||||
/etc/pam.d/sed@{rand6} rw,
|
/etc/pam.d/sed@{rand6} rw,
|
||||||
/etc/pam.d/common-password rw,
|
/etc/pam.d/common-password rw,
|
||||||
|
|
||||||
|
@{efi}/ r,
|
||||||
|
|
||||||
/var/lib/systemd/{,*} rw,
|
/var/lib/systemd/{,*} rw,
|
||||||
/var/log/journal/ rw,
|
/var/log/journal/ rw,
|
||||||
|
|
||||||
profile dpkg {
|
profile dpkg {
|
||||||
include <abstractions/base>
|
include <abstractions/base>
|
||||||
|
include <abstractions/consoles>
|
||||||
include <abstractions/common/apt>
|
include <abstractions/common/apt>
|
||||||
|
|
||||||
capability dac_read_search,
|
capability dac_read_search,
|
||||||
|
|
|
||||||
|
|
@ -16,6 +16,7 @@ profile bootctl @{exec_path} flags=(attach_disconnected,mediate_deleted) {
|
||||||
capability linux_immutable,
|
capability linux_immutable,
|
||||||
capability mknod,
|
capability mknod,
|
||||||
capability net_admin,
|
capability net_admin,
|
||||||
|
capability sys_rawio,
|
||||||
capability sys_resource,
|
capability sys_resource,
|
||||||
|
|
||||||
signal send peer=child-pager,
|
signal send peer=child-pager,
|
||||||
|
|
|
||||||
|
|
@ -17,6 +17,10 @@ profile localectl @{exec_path} {
|
||||||
signal send set=cont peer=child-pager,
|
signal send set=cont peer=child-pager,
|
||||||
|
|
||||||
#aa:dbus talk bus=system name=org.freedesktop.locale1 label="@{p_systemd_localed}"
|
#aa:dbus talk bus=system name=org.freedesktop.locale1 label="@{p_systemd_localed}"
|
||||||
|
dbus send bus=system path=/org/freedesktop/locale1
|
||||||
|
interface=org.freedesktop.DBus.Properties
|
||||||
|
member=GetAll
|
||||||
|
peer=(name=org.freedesktop.locale1),
|
||||||
|
|
||||||
@{exec_path} mr,
|
@{exec_path} mr,
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -17,6 +17,10 @@ profile systemd-localed @{exec_path} flags=(attach_disconnected) {
|
||||||
unix bind type=stream addr=@@{udbus}/bus/systemd-localed/system,
|
unix bind type=stream addr=@@{udbus}/bus/systemd-localed/system,
|
||||||
|
|
||||||
#aa:dbus own bus=system name=org.freedesktop.locale1
|
#aa:dbus own bus=system name=org.freedesktop.locale1
|
||||||
|
dbus send bus=system path=/org/freedesktop/systemd1
|
||||||
|
interface=org.freedesktop.systemd1.Manager
|
||||||
|
member=Reload
|
||||||
|
peer=(name=org.freedesktop.systemd1, label="@{p_systemd}"),
|
||||||
|
|
||||||
@{exec_path} mr,
|
@{exec_path} mr,
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -33,6 +33,7 @@ profile systemd-userdbd @{exec_path} flags=(attach_disconnected,mediate_deleted)
|
||||||
@{att}/@{run}/systemd/notify w,
|
@{att}/@{run}/systemd/notify w,
|
||||||
@{att}/@{run}/systemd/userdb/io.systemd.DynamicUser rw,
|
@{att}/@{run}/systemd/userdb/io.systemd.DynamicUser rw,
|
||||||
@{att}/@{run}/systemd/userdb/io.systemd.Home rw,
|
@{att}/@{run}/systemd/userdb/io.systemd.Home rw,
|
||||||
|
@{att}/@{run}/systemd/userdb/io.systemd.Machine rw,
|
||||||
|
|
||||||
@{run}/systemd/userdb/{,**} rw,
|
@{run}/systemd/userdb/{,**} rw,
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -73,6 +73,7 @@ profile dockerd @{exec_path} flags=(attach_disconnected) {
|
||||||
@{bin}/kmod rCx -> kmod,
|
@{bin}/kmod rCx -> kmod,
|
||||||
@{bin}/ps rPx,
|
@{bin}/ps rPx,
|
||||||
@{sbin}/runc rUx,
|
@{sbin}/runc rUx,
|
||||||
|
@{bin}/runc rUx, #aa:lint ignore
|
||||||
@{bin}/unpigz rix,
|
@{bin}/unpigz rix,
|
||||||
@{sbin}/xtables-nft-multi rCx -> nft,
|
@{sbin}/xtables-nft-multi rCx -> nft,
|
||||||
@{sbin}/xtables-legacy-multi rCx -> nft,
|
@{sbin}/xtables-legacy-multi rCx -> nft,
|
||||||
|
|
|
||||||
|
|
@ -14,6 +14,7 @@ profile kernel-install @{exec_path} {
|
||||||
include <abstractions/disks-read>
|
include <abstractions/disks-read>
|
||||||
include <abstractions/nameservice-strict>
|
include <abstractions/nameservice-strict>
|
||||||
|
|
||||||
|
capability sys_rawio,
|
||||||
capability sys_resource,
|
capability sys_resource,
|
||||||
|
|
||||||
ptrace read peer=@{p_systemd},
|
ptrace read peer=@{p_systemd},
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue