mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2024-11-14 23:43:56 +01:00
Update su
This commit is contained in:
parent
3430e3df90
commit
09fdd074f8
@ -19,6 +19,9 @@ profile su @{exec_path} {
|
||||
capability setgid,
|
||||
capability setuid,
|
||||
#audit deny capability net_bind_service,
|
||||
capability sys_resource,
|
||||
# No clear purpose, deny until needed
|
||||
deny capability net_admin,
|
||||
|
||||
signal (send) set=(term,kill),
|
||||
signal (receive) set=(int,quit,term),
|
||||
@ -45,6 +48,10 @@ profile su @{exec_path} {
|
||||
# For pam_securetty
|
||||
@{PROC}/cmdline r,
|
||||
@{sys}/devices/virtual/tty/console/active r,
|
||||
|
||||
# pseudo-terminal
|
||||
capability chown,
|
||||
/dev/{,pts/}ptmx rw,
|
||||
|
||||
include if exists <local/su>
|
||||
}
|
||||
|
Loading…
Reference in New Issue
Block a user