feat(abs): internal cleanup.

This commit is contained in:
Alexandre Pujol 2024-04-05 23:49:21 +01:00
parent 5c6f9c51b5
commit 4f1f34de3f
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
6 changed files with 20 additions and 11 deletions

View file

@ -8,14 +8,11 @@
# userns,
# Only needed when kernel.unprivileged_userns_clone is set to "1"
capability setgid, # If kernel.unprivileged_userns_clone = 1
capability setuid, # If kernel.unprivileged_userns_clone = 1
capability sys_admin,
capability sys_chroot,
capability setuid,
capability setgid,
owner @{PROC}/@{pid}/setgroups w,
owner @{PROC}/@{pid}/gid_map w,
owner @{PROC}/@{pid}/uid_map w,
capability sys_ptrace,
owner @{HOME}/.pki/ rw,
owner @{HOME}/.pki/nssdb/ rw,
@ -37,4 +34,9 @@
/dev/shm/ r,
owner /dev/shm/.org.chromium.Chromium.* rw,
# If kernel.unprivileged_userns_clone = 1
owner @{PROC}/@{pid}/setgroups w,
owner @{PROC}/@{pid}/gid_map w,
owner @{PROC}/@{pid}/uid_map w,
include if exists <abstractions/common/chromium.d>