feat(profile): remove rules not needed anymore

Moved into the nvidia-strict abs.
This commit is contained in:
Alexandre Pujol 2025-09-13 12:03:00 +02:00
parent bd487d1b66
commit 4982ff104d
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
3 changed files with 1 additions and 6 deletions

View file

@ -33,8 +33,6 @@ profile nvidia-settings @{exec_path} flags=(attach_disconnected) {
/dev/char/@{dynamic}:@{int} w, # For dynamic assignment range 234 to 254, 384 to 511 /dev/char/@{dynamic}:@{int} w, # For dynamic assignment range 234 to 254, 384 to 511
/dev/nvidia-caps/ rw, /dev/nvidia-caps/ rw,
/dev/nvidia-caps/nvidia-cap@{int} r, /dev/nvidia-caps/nvidia-cap@{int} r,
/dev/nvidia-uvm rw,
/dev/nvidia-uvm-tools r,
include if exists <local/nvidia-settings> include if exists <local/nvidia-settings>
} }

View file

@ -26,8 +26,6 @@ profile nvidia-smi @{exec_path} {
/dev/char/@{dynamic}:@{int} w, # For dynamic assignment range 234 to 254, 384 to 511 /dev/char/@{dynamic}:@{int} w, # For dynamic assignment range 234 to 254, 384 to 511
/dev/nvidia-caps/ rw, /dev/nvidia-caps/ rw,
/dev/nvidia-caps/nvidia-cap@{int} rw, /dev/nvidia-caps/nvidia-cap@{int} rw,
/dev/nvidia-uvm rw,
/dev/nvidia-uvm-tools r,
include if exists <local/nvidia-smi> include if exists <local/nvidia-smi>
} }

View file

@ -10,7 +10,7 @@ include <tunables/global>
profile nvtop @{exec_path} flags=(attach_disconnected) { profile nvtop @{exec_path} flags=(attach_disconnected) {
include <abstractions/base> include <abstractions/base>
include <abstractions/consoles> include <abstractions/consoles>
include <abstractions/graphics-full> include <abstractions/graphics>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
capability sys_ptrace, capability sys_ptrace,
@ -54,7 +54,6 @@ profile nvtop @{exec_path} flags=(attach_disconnected) {
@{PROC}/driver/nvidia/capabilities/mig/{config,monitor} r, @{PROC}/driver/nvidia/capabilities/mig/{config,monitor} r,
owner @{PROC}/@{pid}/task/@{tid}/comm rw, owner @{PROC}/@{pid}/task/@{tid}/comm rw,
/dev/dri/ r,
/dev/nvidia-caps/ rw, /dev/nvidia-caps/ rw,
/dev/nvidia-caps/nvidia-cap@{int} rw, /dev/nvidia-caps/nvidia-cap@{int} rw,