feat(profile): remove transparent_hugepage rule already included in base.

This commit is contained in:
Alexandre Pujol 2024-09-08 12:36:35 +01:00
parent 98042620f6
commit 7b04e28835
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
35 changed files with 0 additions and 61 deletions

View file

@ -30,8 +30,6 @@ profile sbctl @{exec_path} {
@{sys}/firmware/efi/efivars/SecureBoot-@{uuid} r,
@{sys}/firmware/efi/efivars/SetupMode-@{uuid} r,
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
/dev/pts/@{int} rw,
# File Inherit

View file

@ -31,8 +31,6 @@ profile sing-box @{exec_path} {
owner @{user_share_dirs}/certmagic/** rw,
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
include if exists <local/sing-box>
}

View file

@ -70,7 +70,6 @@ profile snap @{exec_path} {
@{run}/mount/utab r,
@{run}/snapd.socket rw,
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
@{sys}/kernel/security/apparmor/features/{,**} r,
@{PROC}/@{pids}/cgroup r,

View file

@ -19,8 +19,6 @@ profile snap-failure @{exec_path} {
/var/lib/snapd/sequence/snapd.json r,
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
@{PROC}/cmdline r,
profile systemctl {

View file

@ -20,8 +20,6 @@ profile snap-seccomp @{exec_path} {
/var/lib/snapd/seccomp/bpf/{,**} rw,
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
owner @{PROC}/@{pids}/mountinfo r,
deny @{user_share_dirs}/gvfs-metadata/* r,

View file

@ -47,7 +47,6 @@ profile snap-update-ns @{exec_path} {
@{sys}/fs/cgroup/{,**/} r,
@{sys}/fs/cgroup/system.slice/snap.*.service/cgroup.freeze rw,
@{sys}/fs/cgroup/user.slice/user-@{uid}.slice/user@@{uid}.service/app.slice/snap*.service/cgroup.freeze rw,
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
@{PROC}/@{pids}/cgroup r,
@{PROC}/cmdline r,

View file

@ -153,7 +153,6 @@ profile snapd @{exec_path} {
@{sys}/fs/cgroup/user.slice/ r,
@{sys}/fs/cgroup/user.slice/user-@{uid}.slice/{,**/} r,
@{sys}/kernel/kexec_loaded r,
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
@{sys}/kernel/security/apparmor/features/{,**} r,
@{sys}/kernel/security/apparmor/profiles r,

View file

@ -16,8 +16,6 @@ profile snapd-aa-prompt-listener @{exec_path} {
@{lib_dirs}/snapd/info r,
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
@{PROC}/cmdline r,
include if exists <local/snapd-aa-prompt-listener>

View file

@ -22,8 +22,6 @@ profile snapd-apparmor @{exec_path} {
/var/lib/snapd/apparmor/profiles/ r,
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
@{PROC}/cmdline r,
include if exists <local/snapd-apparmor>

View file

@ -36,8 +36,6 @@ profile syncthing @{exec_path} {
/home/ r,
@{user_sync_dirs}/{,**} rw,
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
@{PROC}/@{pids}/net/route r,
@{PROC}/sys/net/core/somaxconn r,
owner @{PROC}/@{pid}/cgroup r,

View file

@ -37,8 +37,6 @@ profile zsysd @{exec_path} flags=(complain) {
@{PROC}/cmdline r,
@{PROC}/sys/kernel/spl/hostid r,
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
/dev/pts/@{int} rw,
/dev/zfs rw,