Update profiles.

This commit is contained in:
Alexandre Pujol 2022-02-08 18:16:45 +00:00
parent 7274f98fa6
commit 9ecc1aa240
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
10 changed files with 33 additions and 14 deletions

View file

@ -10,9 +10,17 @@ include <tunables/global>
profile systemd-makefs @{exec_path} {
include <abstractions/base>
capability net_admin,
capability sys_resource,
@{exec_path} mr,
/{usr/,}{s,}bin/mkswap rPx,
@{sys}/devices/virtual/block/zram[0-9]*/ r,
@{sys}/devices/virtual/block/zram[0-9]*/** r,
/dev/zram[0-9]* rwk,
include if exists <local/systemd-makefs>
}

View file

@ -15,17 +15,17 @@ profile systemd-udevd @{exec_path} flags=(attach_disconnected complain) {
include <abstractions/consoles>
include <abstractions/systemd-common>
# (##FIXME##)
capability sys_admin,
capability net_admin,
capability dac_read_search,
capability chown,
capability dac_override,
capability dac_read_search,
capability fowner,
capability fsetid,
capability mknod,
capability net_admin,
capability sys_admin,
capability sys_module,
capability sys_ptrace,
capability sys_resource,
capability chown,
capability fsetid,
capability sys_module,
capability mknod,
ptrace (read),