feat(profiles): use /etc read only variable: etc_ro

This commit is contained in:
Alexandre Pujol 2023-02-04 23:34:29 +00:00
parent 6e56cfccc9
commit bac87f9547
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
19 changed files with 33 additions and 32 deletions

View file

@ -139,12 +139,12 @@ profile sddm @{exec_path} {
/{usr/,}lib/@{multiarch}/ld-*.so mr,
/etc/security/limits.d/ r,
@{etc_ro}/security/limits.d/ r,
owner @{HOME}/.Xauthority rw,
/etc/default/locale r,
/etc/environment r,
@{etc_ro}/environment r,
owner @{PROC}/@{pid}/loginuid rw,
owner @{PROC}/@{pid}/mounts r,

View file

@ -48,8 +48,8 @@ profile su @{exec_path} {
/{usr/,}{s,}bin/nologin rPx,
/etc/default/locale r,
/etc/environment r,
/etc/security/limits.d/ r,
@{etc_ro}/environment r,
@{etc_ro}/security/limits.d/ r,
/etc/shells r,
owner @{PROC}/@{pids}/loginuid r,

View file

@ -54,10 +54,10 @@ profile sudo @{exec_path} {
/{usr/,}lib/cockpit/cockpit-askpass rPx,
/{usr/,}lib/molly-guard/molly-guard rPx,
@{etc_ro}/environment r,
@{etc_ro}/security/limits.d/{,*} r,
/etc/default/locale r,
/etc/environment r,
/etc/machine-id r,
/etc/security/limits.d/{,*} r,
/etc/sudo.conf r,
/etc/sudoers r,
/etc/sudoers.d/{,*} r,