update apparmor profiles

Signed-off-by: Alexandre Pujol <alexandre@pujol.io>
This commit is contained in:
Mikhail Morfikov 2022-04-24 11:52:42 +02:00 committed by Alexandre Pujol
parent 85e7f58d3c
commit 35a281d045
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
28 changed files with 147 additions and 38 deletions

View file

@ -28,5 +28,7 @@ profile update-alternatives @{exec_path} {
/usr/** rw,
/lib/firmware/* rw,
include if exists <local/update-alternatives>
}

View file

@ -28,10 +28,13 @@ profile uscan @{exec_path} {
/{usr/,}bin/pwd rix,
/{usr/,}bin/find rix,
/{usr/,}bin/file rix,
/{usr/,}bin/getconf rix,
/{usr/,}bin/tar rix,
/{usr/,}bin/gzip rix,
/{usr/,}bin/bzip2 rix,
/{usr/,}bin/gunzip rix,
/{usr/,}bin/xz rix,
/{usr/,}bin/uupdate rPUx,

View file

@ -15,6 +15,9 @@ profile vsftpd @{exec_path} {
# Only for local users authentication
include <abstractions/authentication>
# For libwrap (TCP Wrapper) support (tcp_wrappers=YES)
include <abstractions/hosts_access>
# To be able to listen on ports < 1024
capability net_bind_service,
@ -48,9 +51,6 @@ profile vsftpd @{exec_path} {
# List of users disallowed FTP access
/etc/ftpusers r,
# For libwrap (TCP Wrapper) support (tcp_wrappers=YES)
/etc/hosts.{allow,deny} r,
# vsftpd config files
/etc/vsftpd.conf r,
/etc/vsftpd/**/ r,

View file

@ -65,7 +65,7 @@ profile yt-dlp @{exec_path} {
# Which files yt-dlp should be able to open
owner /media/**/ r,
owner /media/**.@{ytdlp_ext} rw,
owner /media/**.@{ytdlp_ext} rwk,
owner @{HOME}/.cache/ rw,
owner @{HOME}/.cache/yt-dlp/ rw,