Update profiles.
This commit is contained in:
parent
f922a5f8e8
commit
b2d3af8bca
26 changed files with 57 additions and 37 deletions
|
|
@ -13,6 +13,7 @@ profile systemd-tmpfiles @{exec_path} {
|
|||
include <abstractions/nameservice-strict>
|
||||
|
||||
capability chown,
|
||||
capability dac_override,
|
||||
capability dac_read_search,
|
||||
capability fowner,
|
||||
capability fsetid,
|
||||
|
|
@ -49,9 +50,5 @@ profile systemd-tmpfiles @{exec_path} {
|
|||
|
||||
@{PROC}/@{pid}/net/unix r,
|
||||
|
||||
# Silencer
|
||||
deny network inet6 stream,
|
||||
deny network inet stream,
|
||||
|
||||
include if exists <local/systemd-tmpfiles>
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue