2024-03-26 00:16:00 +01:00
|
|
|
// apparmor.d - Full set of apparmor profiles
|
|
|
|
// Copyright (C) 2021-2024 Alexandre Pujol <alexandre@pujol.io>
|
|
|
|
// SPDX-License-Identifier: GPL-2.0-only
|
|
|
|
|
|
|
|
package builder
|
|
|
|
|
|
|
|
import (
|
2024-10-02 17:22:46 +02:00
|
|
|
"github.com/roddhjav/apparmor.d/pkg/prebuild"
|
2024-03-26 00:16:00 +01:00
|
|
|
"github.com/roddhjav/apparmor.d/pkg/util"
|
|
|
|
)
|
|
|
|
|
|
|
|
var (
|
|
|
|
regFullSystemPolicy = util.ToRegexRepl([]string{
|
|
|
|
`r(PU|U)x,`, `rPx,`,
|
|
|
|
})
|
|
|
|
)
|
|
|
|
|
|
|
|
type FullSystemPolicy struct {
|
2024-10-02 17:22:46 +02:00
|
|
|
prebuild.Base
|
2024-03-26 00:16:00 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
func init() {
|
|
|
|
RegisterBuilder(&FullSystemPolicy{
|
2024-10-02 17:22:46 +02:00
|
|
|
Base: prebuild.Base{
|
2024-03-26 00:16:00 +01:00
|
|
|
Keyword: "fsp",
|
|
|
|
Msg: "Prevent unconfined transitions in profile rules",
|
|
|
|
},
|
|
|
|
})
|
|
|
|
}
|
|
|
|
|
2024-05-25 23:32:10 +02:00
|
|
|
func (b FullSystemPolicy) Apply(opt *Option, profile string) (string, error) {
|
2024-05-25 23:30:20 +02:00
|
|
|
return regFullSystemPolicy.Replace(profile), nil
|
2024-03-26 00:16:00 +01:00
|
|
|
}
|