feat(aa-log): update shell paths.
This commit is contained in:
parent
19b27a26c0
commit
65386321c2
2 changed files with 2 additions and 1 deletions
|
|
@ -71,6 +71,7 @@ var (
|
||||||
// The order the apparmor file rules should be sorted
|
// The order the apparmor file rules should be sorted
|
||||||
fileAlphabet = []string{
|
fileAlphabet = []string{
|
||||||
"@{exec_path}", // 1. entry point
|
"@{exec_path}", // 1. entry point
|
||||||
|
"@{sh_path}", // 2.1 shells
|
||||||
"@{bin}", // 2.1 binaries
|
"@{bin}", // 2.1 binaries
|
||||||
"@{lib}", // 2.2 libraries
|
"@{lib}", // 2.2 libraries
|
||||||
"/opt", // 2.3 opt binaries & libraries
|
"/opt", // 2.3 opt binaries & libraries
|
||||||
|
|
|
||||||
|
|
@ -63,7 +63,7 @@ var (
|
||||||
|
|
||||||
// Some system glob
|
// Some system glob
|
||||||
`:1.[0-9]*`, `:*`, // dbus peer name
|
`:1.[0-9]*`, `:*`, // dbus peer name
|
||||||
`@{bin}/(|ba|da)sh`, `@{bin}/{,ba,da}sh`, // collect all shell
|
`@{bin}/(|ba|da)sh`, `@{sh_path}`, // collect all shell
|
||||||
`@{lib}/modules/[^/]+\/`, `@{lib}/modules/*/`, // strip kernel version numbers from kernel module accesses
|
`@{lib}/modules/[^/]+\/`, `@{lib}/modules/*/`, // strip kernel version numbers from kernel module accesses
|
||||||
`[0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][-_][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][-_][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][-_][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][-_][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F]`, `@{uuid}`,
|
`[0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][-_][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][-_][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][-_][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][-_][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F]`, `@{uuid}`,
|
||||||
`[0-9][0-9][0-9][0-9][0-9][0-9]+`, `@{int}`,
|
`[0-9][0-9][0-9][0-9][0-9][0-9]+`, `@{int}`,
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue