mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2024-11-15 07:54:17 +01:00
/proc/sys/kernel/random/boot_id is part of nameservice-strict.
This commit is contained in:
parent
28ee94c4a5
commit
683da55bb9
@ -54,7 +54,6 @@ profile dbus-daemon @{exec_path} flags=(attach_disconnected) {
|
||||
@{PROC}/1/environ r,
|
||||
@{PROC}/cmdline r,
|
||||
@{PROC}/sys/kernel/osrelease r,
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
|
||||
@{sys}/module/apparmor/parameters/enabled r,
|
||||
|
||||
|
@ -54,7 +54,6 @@ profile gdm @{exec_path} flags=(attach_disconnected) {
|
||||
@{PROC}/1/environ r,
|
||||
@{PROC}/cmdline r,
|
||||
@{PROC}/sys/kernel/osrelease r,
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
|
||||
include if exists <local/gdm>
|
||||
}
|
||||
|
@ -65,7 +65,6 @@ profile gdm-session-worker @{exec_path} flags=(attach_disconnected) {
|
||||
owner @{PROC}/@{pid}/fd/ r,
|
||||
owner @{PROC}/@{pid}/loginuid rw,
|
||||
owner @{PROC}/@{pid}/uid_map r,
|
||||
owner @{PROC}/sys/kernel/random/boot_id r,
|
||||
|
||||
/dev/tty rw,
|
||||
/dev/tty[0-9]* rw,
|
||||
|
@ -46,7 +46,6 @@ profile nautilus @{exec_path} flags=(attach_disconnected) {
|
||||
owner @{PROC}/@{pid}/fd/ r,
|
||||
owner @{PROC}/@{pid}/mountinfo r,
|
||||
owner @{PROC}/@{pid}/net/wireless r,
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
|
||||
@{run}/mount/utab r,
|
||||
@{run}/systemd/userdb/ r,
|
||||
|
@ -30,7 +30,6 @@ profile gvfsd-recent @{exec_path} {
|
||||
owner @{run}/user/@{uid}/gvfsd/socket-[a-zA-z0-9]* rw,
|
||||
|
||||
owner @{PROC}/@{pid}/mountinfo r,
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
|
||||
@{run}/systemd/userdb/ r,
|
||||
@{run}/mount/utab r,
|
||||
|
@ -84,7 +84,6 @@ profile NetworkManager @{exec_path} flags=(attach_disconnected) {
|
||||
@{PROC}/1/environ r,
|
||||
@{PROC}/cmdline r,
|
||||
@{PROC}/sys/kernel/osrelease r,
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
@{PROC}/sys/net/** rw,
|
||||
|
||||
include if exists <local/NetworkManager>
|
||||
|
@ -31,7 +31,6 @@ profile nm-openvpn-service @{exec_path} {
|
||||
/dev/tty rw,
|
||||
|
||||
owner @{PROC}/@{pid}/fd/ r,
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
|
||||
include if exists <local/nm-openvpn-service>
|
||||
}
|
||||
|
@ -14,7 +14,5 @@ profile hostnamectl @{exec_path} {
|
||||
|
||||
/etc/machine-id r,
|
||||
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
|
||||
include if exists <local/hostnamectl>
|
||||
}
|
@ -67,7 +67,6 @@ profile systemd-journald @{exec_path} {
|
||||
@{PROC}/@{pids}/sessionid r,
|
||||
@{PROC}/@{pids}/loginuid r,
|
||||
@{PROC}/@{pids}/cgroup r,
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
@{PROC}/sys/kernel/hostname r,
|
||||
|
||||
/dev/kmsg rw,
|
||||
|
@ -41,7 +41,6 @@ profile systemd-resolved @{exec_path} {
|
||||
@{PROC}/cmdline r,
|
||||
@{PROC}/sys/kernel/hostname r,
|
||||
@{PROC}/sys/kernel/osrelease r,
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
|
||||
# System access
|
||||
@{sys}/firmware/efi/efivars/SecureBoot-@{uuid} r,
|
||||
|
@ -93,7 +93,6 @@ profile systemd-udevd @{exec_path} flags=(attach_disconnected complain) {
|
||||
owner @{PROC}/@{pid}/fd/ r,
|
||||
@{PROC}/@{pids}/cgroup r,
|
||||
@{PROC}/devices r,
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
|
||||
# file_inherit
|
||||
owner @{HOME}/.xsession-errors w,
|
||||
|
@ -25,7 +25,6 @@ profile userdbctl @{exec_path} {
|
||||
@{run}/systemd/userdb/ r,
|
||||
|
||||
@{PROC}/@{pid}/cgroup r,
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
|
||||
include if exists <local/userdbctl>
|
||||
}
|
@ -50,7 +50,6 @@ profile cockpit-bridge @{exec_path} {
|
||||
@{PROC}/1/cgroup r,
|
||||
@{PROC}/cmdline r,
|
||||
@{PROC}/diskstats r,
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
@{PROC}/uptime r,
|
||||
|
||||
/dev/ptmx rw,
|
||||
|
@ -43,7 +43,6 @@ profile cockpit-session @{exec_path} flags=(attach_disconnected) {
|
||||
owner @{PROC}/@{pid}/loginuid rw,
|
||||
owner @{PROC}/@{pid}/uid_map r,
|
||||
@{PROC}/@{pids}/fd/ r,
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
|
||||
include if exists <local/cockpit-session>
|
||||
}
|
@ -48,7 +48,6 @@ profile kwalletd5 @{exec_path} {
|
||||
|
||||
owner @{PROC}/@{pid}/cmdline r,
|
||||
owner @{PROC}/@{pid}/fd/ r,
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
@{PROC}/sys/kernel/core_pattern r,
|
||||
|
||||
owner /tmp/kwalletd5.* rw,
|
||||
|
@ -26,7 +26,5 @@ profile pwck @{exec_path} {
|
||||
|
||||
@{run}/systemd/userdb/ r,
|
||||
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
|
||||
include if exists <local/pwck>
|
||||
}
|
@ -54,7 +54,6 @@ profile qtox @{exec_path} {
|
||||
|
||||
owner @{PROC}/@{pid}/cmdline r,
|
||||
@{PROC}/sys/kernel/core_pattern r, # for KCrash::initialize()
|
||||
@{PROC}/sys/kernel/random/boot_id r, # for QSysInfo::bootUniqueId(), mvoe to qt5 abstraction?
|
||||
|
||||
/usr/share/hwdata/pnp.ids r,
|
||||
|
||||
|
@ -46,7 +46,6 @@ profile su @{exec_path} {
|
||||
/etc/shells r,
|
||||
|
||||
@{PROC}/1/limits r,
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
owner @{PROC}/@{pids}/loginuid r,
|
||||
owner @{PROC}/@{pids}/cgroup r,
|
||||
owner @{PROC}/@{pids}/mountinfo r,
|
||||
|
@ -79,8 +79,6 @@ profile sudo @{exec_path} {
|
||||
@{run}/systemd/userdb/ r,
|
||||
@{run}/systemd/userdb/io.systemd.DynamicUser rw,
|
||||
|
||||
@{PROC}/sys/kernel/random/boot_id r,
|
||||
|
||||
/dev/ r, # interactive login
|
||||
/dev/ptmx rw,
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user