Merge branch 'nobodysu'
* nobodysu: Update su
This commit is contained in:
commit
accf5538bd
1 changed files with 7 additions and 0 deletions
|
|
@ -19,6 +19,9 @@ profile su @{exec_path} {
|
||||||
capability setgid,
|
capability setgid,
|
||||||
capability setuid,
|
capability setuid,
|
||||||
#audit deny capability net_bind_service,
|
#audit deny capability net_bind_service,
|
||||||
|
capability sys_resource,
|
||||||
|
# No clear purpose, deny until needed
|
||||||
|
deny capability net_admin,
|
||||||
|
|
||||||
signal (send) set=(term,kill),
|
signal (send) set=(term,kill),
|
||||||
signal (receive) set=(int,quit,term),
|
signal (receive) set=(int,quit,term),
|
||||||
|
|
@ -46,5 +49,9 @@ profile su @{exec_path} {
|
||||||
@{PROC}/cmdline r,
|
@{PROC}/cmdline r,
|
||||||
@{sys}/devices/virtual/tty/console/active r,
|
@{sys}/devices/virtual/tty/console/active r,
|
||||||
|
|
||||||
|
# pseudo-terminal
|
||||||
|
capability chown,
|
||||||
|
/dev/{,pts/}ptmx rw,
|
||||||
|
|
||||||
include if exists <local/su>
|
include if exists <local/su>
|
||||||
}
|
}
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue