Sudo needs much more cap for normal usage.

This commit is contained in:
Alexandre Pujol 2021-04-03 23:28:16 +01:00
parent 660921f57c
commit 61038bdfa8
Failed to generate hash of commit

View file

@ -30,6 +30,12 @@ profile sudo @{exec_path} {
# Needed? (#FIXME#) # Needed? (#FIXME#)
capability sys_resource, capability sys_resource,
capability net_admin,
capability sys_ptrace,
capability dac_read_search,
capability dac_override,
capability mknod,
ptrace read,
# To remove the following error: # To remove the following error:
# sudo: PAM account management error: Permission denied # sudo: PAM account management error: Permission denied
@ -54,6 +60,7 @@ profile sudo @{exec_path} {
owner @{run}/sudo/ rw, owner @{run}/sudo/ rw,
owner @{run}/sudo/ts/ rw, owner @{run}/sudo/ts/ rw,
owner @{run}/sudo/ts/* rwk, owner @{run}/sudo/ts/* rwk,
@{run}/faillock/{,*} rwk,
@{PROC}/@{pid}/fd/ r, @{PROC}/@{pid}/fd/ r,
@{PROC}/@{pids}/stat r, @{PROC}/@{pids}/stat r,
@ -62,6 +69,8 @@ profile sudo @{exec_path} {
/etc/sudoers r, /etc/sudoers r,
/etc/sudoers.d/{,*} r, /etc/sudoers.d/{,*} r,
/etc/environment r,
/etc/security/limits.d/{,*} r,
# file_inherit # file_inherit
owner /dev/tty[0-9]* rw, owner /dev/tty[0-9]* rw,