From 192d227c50324f44b1781008bf08457da684f32e Mon Sep 17 00:00:00 2001 From: doublez13 Date: Thu, 16 May 2024 07:36:16 -0600 Subject: [PATCH] crontab: Use editor abstraction --- apparmor.d/groups/cron/crontab | 13 +------------ 1 file changed, 1 insertion(+), 12 deletions(-) diff --git a/apparmor.d/groups/cron/crontab b/apparmor.d/groups/cron/crontab index 86e19b93..be876839 100644 --- a/apparmor.d/groups/cron/crontab +++ b/apparmor.d/groups/cron/crontab @@ -35,21 +35,10 @@ profile crontab @{exec_path} { profile editor { include - include + include capability fsetid, - @{bin}/sensible-editor mr, - @{bin}/vim.* mrix, - @{sh_path} rix, - @{bin}/which{,.debianutils} rix, - - owner @{HOME}/.selected_editor r, - - /usr/share/vim/{,**} r, - /etc/vim/{,**} r, - owner @{HOME}/.viminfo{,.tmp} rw, - /tmp/ r, owner @{tmp}/crontab.*/crontab rw,