diff --git a/apparmor.d/groups/ssh/sshd b/apparmor.d/groups/ssh/sshd index 08980197b..54f2afe98 100644 --- a/apparmor.d/groups/ssh/sshd +++ b/apparmor.d/groups/ssh/sshd @@ -48,8 +48,8 @@ profile sshd @{exec_path} flags=(attach_disconnected) { @{exec_path} mrix, - /{usr/,}bin/{,b,d,rb}ash rPUx, - /{usr/,}bin/{c,k,tc,z}sh rPUx, + /{usr/,}bin/{,b,d,rb}ash rUx, + /{usr/,}bin/{c,k,tc,z}sh rUx, /{usr/,}{s,}bin/nologin rPx, /{usr/,}bin/passwd rPx, /{usr/,}lib/openssh/sftp-server rPx, @@ -81,16 +81,15 @@ profile sshd @{exec_path} flags=(attach_disconnected) { @{sys}/fs/cgroup/*/user/*/[0-9]*/ rw, @{sys}/fs/cgroup/systemd/user.slice/user-@{uid}.slice/session-c[0-9]*.scope/ rw, - owner @{PROC}/@{pids}/limits r, - owner @{PROC}/@{pids}/loginuid rw, - owner @{PROC}/@{pids}/mounts r, - owner @{PROC}/@{pids}/oom_adj rw, - owner @{PROC}/@{pids}/oom_score_adj rw, - owner @{PROC}/@{pids}/uid_map r, + owner @{PROC}/@{pid}/limits r, + owner @{PROC}/@{pid}/loginuid rw, + owner @{PROC}/@{pid}/mounts r, + owner @{PROC}/@{pid}/oom_adj rw, + owner @{PROC}/@{pid}/oom_score_adj rw, + owner @{PROC}/@{pid}/uid_map r, @{PROC}/@{pids}/fd/ r, @{PROC}/1/environ r, @{PROC}/cmdline r, - @{PROC}/cmdline r, @{PROC}/filesystems r, @{PROC}/sys/kernel/ngroups_max r,