mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2024-11-14 23:43:56 +01:00
fix(profiles): @{PROC}/@{uid} -> @{PROC}/@{pid}
This commit is contained in:
parent
c148aa978c
commit
3e331bd656
@ -55,7 +55,7 @@ profile xdg-desktop-portal-gtk @{exec_path} {
|
||||
owner @{run}/user/@{uid}/wayland-[0-9]* rw,
|
||||
@{run}/mount/utab r,
|
||||
|
||||
owner @{PROC}/@{uid}/mountinfo r,
|
||||
owner @{PROC}/@{pid}/mountinfo r,
|
||||
|
||||
include if exists <local/xdg-desktop-portal-gtk>
|
||||
}
|
@ -57,17 +57,17 @@ profile mullvad-gui @{exec_path} {
|
||||
@{PROC}/ r,
|
||||
@{PROC}/sys/fs/inotify/max_user_watches r,
|
||||
@{PROC}/sys/kernel/yama/ptrace_scope r,
|
||||
owner @{PROC}/@{uid}/cmdline r,
|
||||
owner @{PROC}/@{uid}/fd/ r,
|
||||
owner @{PROC}/@{uid}/cgroup r,
|
||||
owner @{PROC}/@{uid}/gid_map w,
|
||||
owner @{PROC}/@{uid}/oom_score_adj w,
|
||||
owner @{PROC}/@{uid}/setgroups w,
|
||||
owner @{PROC}/@{uid}/stat r,
|
||||
owner @{PROC}/@{uid}/statm r,
|
||||
owner @{PROC}/@{uid}/task/ r,
|
||||
owner @{PROC}/@{uid}/task/@{tid}/status r,
|
||||
owner @{PROC}/@{uid}/uid_map w,
|
||||
owner @{PROC}/@{pid}/cmdline r,
|
||||
owner @{PROC}/@{pid}/fd/ r,
|
||||
owner @{PROC}/@{pid}/cgroup r,
|
||||
owner @{PROC}/@{pid}/gid_map w,
|
||||
owner @{PROC}/@{pid}/oom_score_adj w,
|
||||
owner @{PROC}/@{pid}/setgroups w,
|
||||
owner @{PROC}/@{pid}/stat r,
|
||||
owner @{PROC}/@{pid}/statm r,
|
||||
owner @{PROC}/@{pid}/task/ r,
|
||||
owner @{PROC}/@{pid}/task/@{tid}/status r,
|
||||
owner @{PROC}/@{pid}/uid_map w,
|
||||
|
||||
/dev/tty rw,
|
||||
|
||||
|
@ -39,7 +39,7 @@ profile flatpak-system-helper @{exec_path} {
|
||||
owner /tmp/ostree-gpg-*/ rw,
|
||||
owner /tmp/ostree-gpg-*/** rwkl -> /tmp/ostree-gpg-*/**,
|
||||
|
||||
owner @{PROC}/@{uid}/fd/ r,
|
||||
owner @{PROC}/@{pid}/fd/ r,
|
||||
|
||||
profile gpg {
|
||||
include <abstractions/base>
|
||||
@ -54,7 +54,7 @@ profile flatpak-system-helper @{exec_path} {
|
||||
owner /tmp/ostree-gpg-*/ r,
|
||||
owner /tmp/ostree-gpg-*/** rwkl -> /tmp/ostree-gpg-*/**,
|
||||
|
||||
owner @{PROC}/@{uid}/fd/ r,
|
||||
owner @{PROC}/@{pid}/fd/ r,
|
||||
|
||||
}
|
||||
|
||||
|
@ -87,7 +87,7 @@ profile mkinitramfs @{exec_path} {
|
||||
/var/tmp/mkinitramfs_*/usr/lib/modules/*/modules.{order,builtin} rw,
|
||||
owner /var/tmp/mkinitramfs-* rw,
|
||||
|
||||
owner @{PROC}/@{uid}/fd/ r,
|
||||
owner @{PROC}/@{pid}/fd/ r,
|
||||
@{PROC}/cmdline r,
|
||||
@{PROC}/modules r,
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user