Update runsvdir
This commit is contained in:
parent
54d7f0ad7e
commit
d72ed574ce
1 changed files with 62 additions and 0 deletions
|
|
@ -1 +1,63 @@
|
||||||
|
|
||||||
|
# apparmor.d - Full set of apparmor profiles
|
||||||
|
# Copyright (C) 2022 Alexandre Pujol <alexandre@pujol.io>
|
||||||
|
# Copyright (C) 2024 Besanon <m231009ts@mailfence.com>
|
||||||
|
# SPDX-License-Identifier: GPL-2.0-only
|
||||||
|
|
||||||
|
abi <abi/3.0>,
|
||||||
|
|
||||||
|
include <tunables/global>
|
||||||
|
|
||||||
|
@{exec_pathrunsvdir} = @{bin}/runsvdir
|
||||||
|
profile runsvdir @{exec_pathrunsvdir} flags=(attach_disconnected) {
|
||||||
|
include <abstractions/base>
|
||||||
|
include <abstractions/bus-session>
|
||||||
|
include <abstractions/bus-system>
|
||||||
|
include <abstractions/consoles>
|
||||||
|
include <abstractions/nameservice-strict>
|
||||||
|
|
||||||
|
capability setgid,
|
||||||
|
capability setuid,
|
||||||
|
capability kill,
|
||||||
|
|
||||||
|
signal (send) set=(term, cont, kill),
|
||||||
|
signal (send) set=(term) peer=/etc/runit/2,
|
||||||
|
signal (receive) peer=runit,
|
||||||
|
signal (receive) peer=runsv,
|
||||||
|
signal (receive) peer=sddm,
|
||||||
|
|
||||||
|
ptrace (read) peer=elogind,
|
||||||
|
|
||||||
|
@{exec_pathrunsvdir} mr,
|
||||||
|
|
||||||
|
@{bin}/dbus-send rix,
|
||||||
|
@{bin}/runsv rPx,
|
||||||
|
@{bin}/bash rix,
|
||||||
|
@{bin}/utmpset rix,
|
||||||
|
@{bin}/mountpoint rix,
|
||||||
|
/etc/sv/**/run rix,
|
||||||
|
/etc/sv/**/**/run rix,
|
||||||
|
/etc/sv/**/finish rix,
|
||||||
|
/etc/sv/**/run rix,
|
||||||
|
/etc/sv/dbus/check rix,
|
||||||
|
|
||||||
|
owner / r,
|
||||||
|
|
||||||
|
/etc/elogind/logind.conf rw,
|
||||||
|
/etc/machine-id r,
|
||||||
|
/etc/sv/ r,
|
||||||
|
/etc/sv/** rw,
|
||||||
|
/etc/runit/ r,
|
||||||
|
/etc/runit/** rw,
|
||||||
|
|
||||||
|
owner /dev/tty@{int} rw,
|
||||||
|
owner /dev/console rwk,
|
||||||
|
owner /dev/input/event@{int} rw,
|
||||||
|
|
||||||
|
owner /var/log/audit/** rw,
|
||||||
|
/var/lib/dbus/machine-id r,
|
||||||
|
|
||||||
|
owner /tmp/#@{int}* rw,
|
||||||
|
owner /tmp/*/{,s} rw,
|
||||||
|
|
||||||
|
}
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue