mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2024-11-15 16:03:51 +01:00
feat(abs): cleanup sudo abs.
This commit is contained in:
parent
2324da2fa7
commit
5c6f9c51b5
@ -40,23 +40,25 @@
|
||||
|
||||
/ r,
|
||||
|
||||
@{PROC}/@{pid}/limits r,
|
||||
@{PROC}/@{pid}/loginuid r,
|
||||
@{PROC}/@{pid}/stat r,
|
||||
@{PROC}/sys/kernel/cap_last_cap r,
|
||||
@{PROC}/sys/kernel/ngroups_max r,
|
||||
@{PROC}/sys/kernel/seccomp/actions_avail r,
|
||||
|
||||
owner /var/lib/sudo/ts/ rw,
|
||||
owner /var/lib/sudo/ts/@{uid} rwk,
|
||||
owner /var/log/sudo.log wk,
|
||||
|
||||
owner @{HOME}/.sudo_as_admin_successful rw,
|
||||
|
||||
@{run}/faillock/{,*} rwk,
|
||||
|
||||
owner @{run}/sudo/ rw,
|
||||
owner @{run}/sudo/ts/ rw,
|
||||
owner @{run}/sudo/ts/@{uid} rwk,
|
||||
|
||||
@{PROC}/@{pid}/limits r,
|
||||
@{PROC}/@{pid}/loginuid r,
|
||||
@{PROC}/@{pid}/stat r,
|
||||
@{PROC}/sys/kernel/cap_last_cap r,
|
||||
@{PROC}/sys/kernel/ngroups_max r,
|
||||
@{PROC}/sys/kernel/seccomp/actions_avail r,
|
||||
|
||||
/dev/ r,
|
||||
/dev/ptmx rwk,
|
||||
/dev/tty rwk,
|
||||
|
@ -41,8 +41,6 @@ profile sudo @{exec_path} flags=(attach_disconnected) {
|
||||
/var/lib/sudo/lectured/ r,
|
||||
owner /var/lib/sudo/lectured/@{uid} rw,
|
||||
|
||||
owner @{HOME}/.sudo_as_admin_successful rw,
|
||||
|
||||
@{run}/ r,
|
||||
@{run}/systemd/sessions/* r,
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user