Update profiles.

This commit is contained in:
Alexandre Pujol 2022-02-08 18:16:45 +00:00
parent 7274f98fa6
commit 9ecc1aa240
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
10 changed files with 33 additions and 14 deletions

View file

@ -16,6 +16,7 @@ profile apparmor_parser @{exec_path} flags=(attach_disconnected) {
/etc/apparmor/{,**} r,
/etc/apparmor.d/{,**} r,
/etc/apparmor.d/cache.d/{,**} rw,
owner /var/cache/apparmor/{,**} rw,
owner /var/lib/docker/tmp/docker-default[0-9]* r,

View file

@ -14,6 +14,7 @@ profile auditd @{exec_path} {
capability audit_control,
capability chown,
capability fsetid,
capability sys_nice,
capability sys_resource,
network netlink raw,
@ -24,11 +25,13 @@ profile auditd @{exec_path} {
/var/log/audit/{,**} rw,
@{run}/auditd.pid rw,
@{run}/systemd/userdb/ r,
owner @{PROC}/@{pid}/attr/current r,
owner @{PROC}/@{pid}/loginuid r,
owner @{PROC}/@{pid}/oom_score_adj r,
owner @{PROC}/@{pid}/sessionid r,
owner @{PROC}/@{pid}/oom_score_adj rw,
include if exists <local/auditd>
}

View file

@ -23,6 +23,7 @@ profile firecfg @{exec_path} flags=(attach_disconnected) {
/etc/login.defs r,
/etc/firejail/firejail.users r,
/etc/firejail/firecfg.config r,
/usr/local/bin/ r,
/usr/local/bin/* rw,

View file

@ -38,6 +38,7 @@ profile fusermount @{exec_path} {
umount @{MOUNTS}/*/*/,
umount /tmp/.mount_*/,
umount @{run}/user/@{uid}/doc/,
umount @{run}/user/@{uid}/gvfs/,
/etc/fuse.conf r,