feat(profile): improve support for some profiles.

Most of the rules have come from the integration tests.
This commit is contained in:
Alexandre Pujol 2024-11-12 22:18:11 +00:00
parent e4f0f06648
commit 66455a9251
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
29 changed files with 50 additions and 22 deletions

View file

@ -30,8 +30,10 @@ profile ip @{exec_path} flags=(attach_disconnected) {
umount /sys/,
@{exec_path} mrix,
# To run command with 'ip netns exec'
@{shells_path} rUx,
@{bin}/sudo rPx,
@{bin}/sudo rPx,
@{att}/ r,
@ -40,6 +42,7 @@ profile ip @{exec_path} flags=(attach_disconnected) {
/usr/share/iproute2/{,**} r,
@{run}/netns/ r,
@{run}/netns/* rw,
owner @{run}/netns/ rwk,

View file

@ -35,6 +35,7 @@ profile lspci @{exec_path} flags=(attach_disconnected) {
@{sys}/bus/pci/devices/ r,
@{sys}/bus/pci/slots/ r,
@{sys}/bus/pci/slots/@{int}-@{int}/address r,
@{sys}/bus/pci/slots/@{int}/address r,
@{sys}/devices/@{pci}/** r,
@{sys}/module/compression r,