feat(profile): restrict some access to @{PROC}/@{pid}.

This commit is contained in:
Alexandre Pujol 2024-09-25 14:00:29 +01:00
parent 90a8e44d20
commit 28b32f1ae3
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
10 changed files with 31 additions and 22 deletions

View file

@ -44,8 +44,8 @@ profile protonmail-bridge-core @{exec_path} {
owner /var/tmp/etilqs_@{hex16} rw,
@{PROC}/ r,
@{PROC}/1/cgroup r,
@{PROC}/sys/net/core/somaxconn r,
@{PROC}/@{pid}/cgroup r,
deny @{bin}/pass x,
deny owner @{user_password_store_dirs}/** r,