feat(profile): remove transparent_hugepage rule already included in base.
This commit is contained in:
parent
98042620f6
commit
7b04e28835
35 changed files with 0 additions and 61 deletions
|
|
@ -30,8 +30,6 @@ profile sbctl @{exec_path} {
|
|||
@{sys}/firmware/efi/efivars/SecureBoot-@{uuid} r,
|
||||
@{sys}/firmware/efi/efivars/SetupMode-@{uuid} r,
|
||||
|
||||
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
|
||||
|
||||
/dev/pts/@{int} rw,
|
||||
|
||||
# File Inherit
|
||||
|
|
|
|||
|
|
@ -31,8 +31,6 @@ profile sing-box @{exec_path} {
|
|||
|
||||
owner @{user_share_dirs}/certmagic/** rw,
|
||||
|
||||
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
|
||||
|
||||
include if exists <local/sing-box>
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -70,7 +70,6 @@ profile snap @{exec_path} {
|
|||
@{run}/mount/utab r,
|
||||
@{run}/snapd.socket rw,
|
||||
|
||||
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
|
||||
@{sys}/kernel/security/apparmor/features/{,**} r,
|
||||
|
||||
@{PROC}/@{pids}/cgroup r,
|
||||
|
|
|
|||
|
|
@ -19,8 +19,6 @@ profile snap-failure @{exec_path} {
|
|||
|
||||
/var/lib/snapd/sequence/snapd.json r,
|
||||
|
||||
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
|
||||
|
||||
@{PROC}/cmdline r,
|
||||
|
||||
profile systemctl {
|
||||
|
|
|
|||
|
|
@ -20,8 +20,6 @@ profile snap-seccomp @{exec_path} {
|
|||
|
||||
/var/lib/snapd/seccomp/bpf/{,**} rw,
|
||||
|
||||
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
|
||||
|
||||
owner @{PROC}/@{pids}/mountinfo r,
|
||||
|
||||
deny @{user_share_dirs}/gvfs-metadata/* r,
|
||||
|
|
|
|||
|
|
@ -47,7 +47,6 @@ profile snap-update-ns @{exec_path} {
|
|||
@{sys}/fs/cgroup/{,**/} r,
|
||||
@{sys}/fs/cgroup/system.slice/snap.*.service/cgroup.freeze rw,
|
||||
@{sys}/fs/cgroup/user.slice/user-@{uid}.slice/user@@{uid}.service/app.slice/snap*.service/cgroup.freeze rw,
|
||||
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
|
||||
|
||||
@{PROC}/@{pids}/cgroup r,
|
||||
@{PROC}/cmdline r,
|
||||
|
|
|
|||
|
|
@ -153,7 +153,6 @@ profile snapd @{exec_path} {
|
|||
@{sys}/fs/cgroup/user.slice/ r,
|
||||
@{sys}/fs/cgroup/user.slice/user-@{uid}.slice/{,**/} r,
|
||||
@{sys}/kernel/kexec_loaded r,
|
||||
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
|
||||
@{sys}/kernel/security/apparmor/features/{,**} r,
|
||||
@{sys}/kernel/security/apparmor/profiles r,
|
||||
|
||||
|
|
|
|||
|
|
@ -16,8 +16,6 @@ profile snapd-aa-prompt-listener @{exec_path} {
|
|||
|
||||
@{lib_dirs}/snapd/info r,
|
||||
|
||||
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
|
||||
|
||||
@{PROC}/cmdline r,
|
||||
|
||||
include if exists <local/snapd-aa-prompt-listener>
|
||||
|
|
|
|||
|
|
@ -22,8 +22,6 @@ profile snapd-apparmor @{exec_path} {
|
|||
|
||||
/var/lib/snapd/apparmor/profiles/ r,
|
||||
|
||||
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
|
||||
|
||||
@{PROC}/cmdline r,
|
||||
|
||||
include if exists <local/snapd-apparmor>
|
||||
|
|
|
|||
|
|
@ -36,8 +36,6 @@ profile syncthing @{exec_path} {
|
|||
/home/ r,
|
||||
@{user_sync_dirs}/{,**} rw,
|
||||
|
||||
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
|
||||
|
||||
@{PROC}/@{pids}/net/route r,
|
||||
@{PROC}/sys/net/core/somaxconn r,
|
||||
owner @{PROC}/@{pid}/cgroup r,
|
||||
|
|
|
|||
|
|
@ -37,8 +37,6 @@ profile zsysd @{exec_path} flags=(complain) {
|
|||
@{PROC}/cmdline r,
|
||||
@{PROC}/sys/kernel/spl/hostid r,
|
||||
|
||||
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
|
||||
|
||||
/dev/pts/@{int} rw,
|
||||
/dev/zfs rw,
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue