Update profiles.
This commit is contained in:
parent
7274f98fa6
commit
9ecc1aa240
10 changed files with 33 additions and 14 deletions
|
|
@ -10,9 +10,17 @@ include <tunables/global>
|
|||
profile systemd-makefs @{exec_path} {
|
||||
include <abstractions/base>
|
||||
|
||||
capability net_admin,
|
||||
capability sys_resource,
|
||||
|
||||
@{exec_path} mr,
|
||||
|
||||
/{usr/,}{s,}bin/mkswap rPx,
|
||||
|
||||
@{sys}/devices/virtual/block/zram[0-9]*/ r,
|
||||
@{sys}/devices/virtual/block/zram[0-9]*/** r,
|
||||
|
||||
/dev/zram[0-9]* rwk,
|
||||
|
||||
include if exists <local/systemd-makefs>
|
||||
}
|
||||
|
|
@ -15,17 +15,17 @@ profile systemd-udevd @{exec_path} flags=(attach_disconnected complain) {
|
|||
include <abstractions/consoles>
|
||||
include <abstractions/systemd-common>
|
||||
|
||||
# (##FIXME##)
|
||||
capability sys_admin,
|
||||
capability net_admin,
|
||||
capability dac_read_search,
|
||||
capability chown,
|
||||
capability dac_override,
|
||||
capability dac_read_search,
|
||||
capability fowner,
|
||||
capability fsetid,
|
||||
capability mknod,
|
||||
capability net_admin,
|
||||
capability sys_admin,
|
||||
capability sys_module,
|
||||
capability sys_ptrace,
|
||||
capability sys_resource,
|
||||
capability chown,
|
||||
capability fsetid,
|
||||
capability sys_module,
|
||||
capability mknod,
|
||||
|
||||
ptrace (read),
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue