Update profiles.

This commit is contained in:
Alexandre Pujol 2021-06-29 19:55:56 +01:00
parent d084023120
commit ab5958c511
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
13 changed files with 29 additions and 12 deletions

View file

@ -15,12 +15,11 @@ profile systemd-coredump @{exec_path} flags=(attach_disconnected complain) {
include <abstractions/systemd-common>
capability dac_read_search,
capability net_admin,
capability setgid,
capability setpcap,
capability setuid,
capability sys_ptrace,
# Needed?
# deny capability net_admin,
@{exec_path} mr,
@ -31,9 +30,7 @@ profile systemd-coredump @{exec_path} flags=(attach_disconnected complain) {
/etc/systemd/coredump.conf r,
/var/lib/systemd/coredump/ r,
/var/lib/systemd/coredump/#[0-9]* rwl,
/var/lib/systemd/coredump/core.*.@{uid}.[0-9a-f]*.[0-9]*.[0-9]*.zst rwl,
/var/lib/systemd/coredump/core.*.@{uid}.[0-9a-f]*.[0-9]*.[0-9]* rwl,
/var/lib/systemd/coredump/** rwl,
owner @{PROC}/@{pid}/setgroups r,
@{PROC}/@{pids}/comm r,