mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2025-01-18 08:58:15 +01:00
Sudo needs much more cap for normal usage.
This commit is contained in:
parent
660921f57c
commit
61038bdfa8
1 changed files with 9 additions and 0 deletions
|
@ -30,6 +30,12 @@ profile sudo @{exec_path} {
|
||||||
|
|
||||||
# Needed? (#FIXME#)
|
# Needed? (#FIXME#)
|
||||||
capability sys_resource,
|
capability sys_resource,
|
||||||
|
capability net_admin,
|
||||||
|
capability sys_ptrace,
|
||||||
|
capability dac_read_search,
|
||||||
|
capability dac_override,
|
||||||
|
capability mknod,
|
||||||
|
ptrace read,
|
||||||
|
|
||||||
# To remove the following error:
|
# To remove the following error:
|
||||||
# sudo: PAM account management error: Permission denied
|
# sudo: PAM account management error: Permission denied
|
||||||
|
@ -54,6 +60,7 @@ profile sudo @{exec_path} {
|
||||||
owner @{run}/sudo/ rw,
|
owner @{run}/sudo/ rw,
|
||||||
owner @{run}/sudo/ts/ rw,
|
owner @{run}/sudo/ts/ rw,
|
||||||
owner @{run}/sudo/ts/* rwk,
|
owner @{run}/sudo/ts/* rwk,
|
||||||
|
@{run}/faillock/{,*} rwk,
|
||||||
|
|
||||||
@{PROC}/@{pid}/fd/ r,
|
@{PROC}/@{pid}/fd/ r,
|
||||||
@{PROC}/@{pids}/stat r,
|
@{PROC}/@{pids}/stat r,
|
||||||
|
@ -62,6 +69,8 @@ profile sudo @{exec_path} {
|
||||||
|
|
||||||
/etc/sudoers r,
|
/etc/sudoers r,
|
||||||
/etc/sudoers.d/{,*} r,
|
/etc/sudoers.d/{,*} r,
|
||||||
|
/etc/environment r,
|
||||||
|
/etc/security/limits.d/{,*} r,
|
||||||
|
|
||||||
# file_inherit
|
# file_inherit
|
||||||
owner /dev/tty[0-9]* rw,
|
owner /dev/tty[0-9]* rw,
|
||||||
|
|
Loading…
Reference in a new issue