mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2024-11-14 23:43:56 +01:00
feat(full): disable nnp flag on some services.
This commit is contained in:
parent
f564347580
commit
96ea9d17ae
@ -200,6 +200,11 @@ func SetFullSystemPolicy() error {
|
||||
return err
|
||||
}
|
||||
|
||||
// Set systemd unit drop-in files
|
||||
if err := copyTo(paths.New("systemd/full/"), Root.Join("systemd")); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
logging.Success("Configure AppArmor for full system policy")
|
||||
return nil
|
||||
}
|
||||
|
2
systemd/full/system/ModemManager.service
Normal file
2
systemd/full/system/ModemManager.service
Normal file
@ -0,0 +1,2 @@
|
||||
[Service]
|
||||
NoNewPrivileges=no
|
2
systemd/full/system/e2scrub_reap.service
Normal file
2
systemd/full/system/e2scrub_reap.service
Normal file
@ -0,0 +1,2 @@
|
||||
[Service]
|
||||
NoNewPrivileges=no
|
3
systemd/full/system/fwupd-refresh.service
Normal file
3
systemd/full/system/fwupd-refresh.service
Normal file
@ -0,0 +1,3 @@
|
||||
[Service]
|
||||
ProtectKernelModules=no
|
||||
RestrictRealtime=no
|
2
systemd/full/system/irqbalance.service
Normal file
2
systemd/full/system/irqbalance.service
Normal file
@ -0,0 +1,2 @@
|
||||
[Service]
|
||||
NoNewPrivileges=no
|
2
systemd/full/system/rngd.service
Normal file
2
systemd/full/system/rngd.service
Normal file
@ -0,0 +1,2 @@
|
||||
[Service]
|
||||
NoNewPrivileges=no
|
2
systemd/full/system/systemd-homed.service
Normal file
2
systemd/full/system/systemd-homed.service
Normal file
@ -0,0 +1,2 @@
|
||||
[Service]
|
||||
NoNewPrivileges=no
|
2
systemd/full/system/systemd-hostnamed.service
Normal file
2
systemd/full/system/systemd-hostnamed.service
Normal file
@ -0,0 +1,2 @@
|
||||
[Service]
|
||||
NoNewPrivileges=no
|
3
systemd/full/system/systemd-journald.service
Normal file
3
systemd/full/system/systemd-journald.service
Normal file
@ -0,0 +1,3 @@
|
||||
[Service]
|
||||
NoNewPrivileges=no
|
||||
ProtectClock=no
|
2
systemd/full/system/systemd-localed.service
Normal file
2
systemd/full/system/systemd-localed.service
Normal file
@ -0,0 +1,2 @@
|
||||
[Service]
|
||||
NoNewPrivileges=no
|
3
systemd/full/system/systemd-logind.service
Normal file
3
systemd/full/system/systemd-logind.service
Normal file
@ -0,0 +1,3 @@
|
||||
[Service]
|
||||
NoNewPrivileges=no
|
||||
ProtectClock=no
|
2
systemd/full/system/systemd-timedated.service
Normal file
2
systemd/full/system/systemd-timedated.service
Normal file
@ -0,0 +1,2 @@
|
||||
[Service]
|
||||
NoNewPrivileges=no
|
2
systemd/full/system/systemd-userdbd.service
Normal file
2
systemd/full/system/systemd-userdbd.service
Normal file
@ -0,0 +1,2 @@
|
||||
[Service]
|
||||
NoNewPrivileges=no
|
2
systemd/full/system/upower.service
Normal file
2
systemd/full/system/upower.service
Normal file
@ -0,0 +1,2 @@
|
||||
[Service]
|
||||
NoNewPrivileges=no
|
3
systemd/full/system/user@.service
Normal file
3
systemd/full/system/user@.service
Normal file
@ -0,0 +1,3 @@
|
||||
# TODO: works as intended on server, does not work on desktop
|
||||
# [Service]
|
||||
# AppArmorProfile=systemd-user
|
Loading…
Reference in New Issue
Block a user