feat(profiles): general update.

This commit is contained in:
Alexandre Pujol 2023-09-15 22:01:08 +01:00
parent 1d68b5bbc4
commit 6a78b17d23
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
22 changed files with 62 additions and 35 deletions

View file

@ -17,8 +17,6 @@ profile mkinitcpio @{exec_path} flags=(attach_disconnected) {
capability sys_admin,
capability sys_chroot,
unix (receive) type=stream,
@{exec_path} rmix,
@{bin}/{,ba}sh rix,
@ -116,9 +114,10 @@ profile mkinitcpio @{exec_path} flags=(attach_disconnected) {
# Inherit silencer
deny @{HOME}/** r,
deny network inet6 stream,
deny network inet stream,
deny /apparmor/.null rw,
deny network inet stream,
deny network inet6 stream,
deny unix (receive) type=stream,
include if exists <local/mkinitcpio>
}

View file

@ -30,17 +30,12 @@ profile pacman @{exec_path} {
capability sys_chroot,
capability sys_resource,
# network unix stream,
# network unix dgram,
network inet stream,
network inet6 stream,
network inet dgram,
network inet6 dgram,
network netlink raw,
unix (receive) type=stream,
ptrace (read),
@{exec_path} mrix,
@ -161,8 +156,9 @@ profile pacman @{exec_path} {
owner /dev/pts/@{int} rw,
# Silencer,
deny /tmp/ r,
deny @{HOME}/ r,
deny /tmp/ r,
deny unix (receive) type=stream,
profile gpg {
include <abstractions/base>

View file

@ -13,8 +13,6 @@ profile pacman-hook-dkms @{exec_path} {
capability dac_read_search,
capability mknod,
unix (receive) type=stream,
@{exec_path} mr,
@{bin}/bash rix,
@ -30,9 +28,10 @@ profile pacman-hook-dkms @{exec_path} {
/dev/tty rw,
# Inherit Silencer
deny network inet6 stream,
deny network inet stream,
deny /apparmor/.null rw,
deny network inet stream,
deny network inet6 stream,
deny unix (receive) type=stream,
include if exists <local/pacman-hook-dkms>
}

View file

@ -14,7 +14,7 @@ profile pacman-hook-mkinitcpio @{exec_path} flags=(attach_disconnected) {
capability dac_read_search,
capability mknod,
unix (receive) type=stream,
audit deny unix (receive) type=stream,
@{exec_path} mr,
@ -37,11 +37,13 @@ profile pacman-hook-mkinitcpio @{exec_path} flags=(attach_disconnected) {
/etc/mkinitcpio.d/*.preset{,.pacsave} rw,
/ r,
/boot/ r,
/boot/vmlinuz-* rw,
/boot/initramfs-*.img rw,
/boot/initramfs-*-fallback.img rw,
/dev/tty rw,
owner /dev/pts/@{int} rw,
# # Inherit Silencer
deny network inet6 stream,