Update su

This commit is contained in:
nobodysu 2021-12-12 18:16:30 +00:00 committed by GitHub
parent 3430e3df90
commit 09fdd074f8
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -19,6 +19,9 @@ profile su @{exec_path} {
capability setgid,
capability setuid,
#audit deny capability net_bind_service,
capability sys_resource,
# No clear purpose, deny until needed
deny capability net_admin,
signal (send) set=(term,kill),
signal (receive) set=(int,quit,term),
@ -45,6 +48,10 @@ profile su @{exec_path} {
# For pam_securetty
@{PROC}/cmdline r,
@{sys}/devices/virtual/tty/console/active r,
# pseudo-terminal
capability chown,
/dev/{,pts/}ptmx rw,
include if exists <local/su>
}