feat(fsp): systemd drop in files: configure stacked profile

It comes as a replacement of old and unsecure config that was disabling the nnp flag.
The new solution is:
1. Safe
2. Scalable  as hundred of profile could be configured this way
This commit is contained in:
Alexandre Pujol 2025-05-26 23:31:35 +02:00
parent 4ffbf84a00
commit 8f3f3816ed
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
29 changed files with 29 additions and 38 deletions

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&ModemManager

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&archlinux-keyring-wkd-sync

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&systemd-hostnamed

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&systemd-importd

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&systemd-localed

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&systemd-logind

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&systemd-machined

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&systemd-timedated

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&e2scrub

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&e2scrub_all

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&fprintd

View file

@ -1,4 +1,2 @@
[Service] [Service]
ProtectKernelModules=no AppArmorProfile=&fwupdmgr
RestrictRealtime=no
ProtectKernelModules=no

View file

@ -1,6 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&geoclue
MemoryDenyWriteExecute=no
ProtectKernelTunables=no
ProtectKernelModules=no
RestrictRealtime=no

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&irqbalance

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&nm-priv-helper

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&polkitd

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&rngd

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&systemd-homed

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&systemd-hostnamed

View file

@ -1,3 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&systemd-journald
ProtectClock=no

View file

@ -1,3 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&systemd-journald
ProtectClock=no

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&systemd-localed

View file

@ -1,3 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&systemd-logind
ProtectClock=no

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&systemd-machined

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&systemd-networkd

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&systemd-resolved

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&systemd-timedated

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&systemd-userdbd

View file

@ -1,2 +1,2 @@
[Service] [Service]
NoNewPrivileges=no AppArmorProfile=&upowerd