fix: minor profiles fixes.
This commit is contained in:
parent
4f10cf802e
commit
b9fb4b72d2
6 changed files with 11 additions and 8 deletions
|
|
@ -31,7 +31,7 @@ profile systemd-journald @{exec_path} {
|
|||
@{run}/log/ rw,
|
||||
/{run,var}/log/journal/ rw,
|
||||
/{run,var}/log/journal/@{md5}/ rw,
|
||||
/{run,var}/log/journal/@{md5}/* rw -> /{run,var}/log/journal/@{md5}/#@{int},
|
||||
/{run,var}/log/journal/@{md5}/* rwl -> /{run,var}/log/journal/@{md5}/#@{int},
|
||||
|
||||
owner @{run}/systemd/journal/{,**} rw,
|
||||
owner @{run}/systemd/notify rw,
|
||||
|
|
|
|||
|
|
@ -119,7 +119,7 @@ profile systemd-udevd @{exec_path} flags=(attach_disconnected,complain) {
|
|||
|
||||
deny /apparmor/.null rw,
|
||||
|
||||
profile systemctl {
|
||||
profile systemctl flags=(attach_disconnected,complain) {
|
||||
include <abstractions/base>
|
||||
include <abstractions/systemd-common>
|
||||
|
||||
|
|
|
|||
|
|
@ -19,7 +19,7 @@ profile aa-enforce @{exec_path} {
|
|||
@{bin}/ r,
|
||||
@{bin}/apparmor_parser rPx,
|
||||
|
||||
/usr/share/terminfo/x/* r,
|
||||
/usr/share/terminfo/{,**} r,
|
||||
|
||||
/etc/apparmor/logprof.conf r,
|
||||
/etc/apparmor.d/{,**} rw,
|
||||
|
|
|
|||
|
|
@ -1,5 +1,6 @@
|
|||
# apparmor.d - Full set of apparmor profiles
|
||||
# Copyright (C) 2019-2021 Mikhail Morfikov
|
||||
# Copyright (C) 2021-2023 Alexandre Pujol <alexandre@pujol.io>
|
||||
# SPDX-License-Identifier: GPL-2.0-only
|
||||
|
||||
abi <abi/3.0>,
|
||||
|
|
@ -42,12 +43,12 @@ profile adduser @{exec_path} {
|
|||
/etc/adduser.conf r,
|
||||
/etc/skel/{,.*} r,
|
||||
|
||||
@{run}/adduser wk,
|
||||
|
||||
# To create user dirs and copy files from /etc/skel/ to them
|
||||
@{HOME}/ rw,
|
||||
@{HOME}/.* w,
|
||||
/var/lib/*/{,*} rw,
|
||||
|
||||
@{run}/adduser wk,
|
||||
|
||||
include if exists <local/adduser>
|
||||
}
|
||||
|
|
|
|||
|
|
@ -102,6 +102,7 @@ profile snap @{exec_path} {
|
|||
owner @{HOME}/.snap/gnupg/ rw,
|
||||
owner @{HOME}/.snap/gnupg/** rwkl,
|
||||
|
||||
include if exists <local/snap_gpg>
|
||||
}
|
||||
|
||||
include if exists <local/snap>
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue