mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2024-11-15 07:54:17 +01:00
Disk mount fix.
This commit is contained in:
parent
4a35b7d804
commit
a5ec3e559c
@ -13,6 +13,8 @@ profile mount @{exec_path} flags=(complain) {
|
|||||||
include <abstractions/disks-write>
|
include <abstractions/disks-write>
|
||||||
include <abstractions/nameservice-strict>
|
include <abstractions/nameservice-strict>
|
||||||
|
|
||||||
|
capability chown,
|
||||||
|
|
||||||
# To be able to mount anything
|
# To be able to mount anything
|
||||||
# mount("/dev/sdb1", "/mnt", "ext4", 0, NULL) = -1 EPERM (Operation not permitted)
|
# mount("/dev/sdb1", "/mnt", "ext4", 0, NULL) = -1 EPERM (Operation not permitted)
|
||||||
# write(2, "/mnt: permission denied.", 24) = 24
|
# write(2, "/mnt: permission denied.", 24) = 24
|
||||||
|
@ -107,6 +107,8 @@ profile udisksd @{exec_path} flags=(attach_disconnected) {
|
|||||||
@{sys}/class/ r,
|
@{sys}/class/ r,
|
||||||
|
|
||||||
@{sys}/devices/pci[0-9]*/**/{ata,usb,mmc}[0-9]/{,**/}uevent w,
|
@{sys}/devices/pci[0-9]*/**/{ata,usb,mmc}[0-9]/{,**/}uevent w,
|
||||||
|
@{sys}/devices/virtual/block/dm-[0-9]*/ w,
|
||||||
|
@{sys}/devices/virtual/block/dm-[0-9]*/** w,
|
||||||
|
|
||||||
# For powering off USB devices
|
# For powering off USB devices
|
||||||
@{sys}/devices/pci[0-9]*/**/{ata,usb,mmc}[0-9]/{,**/}remove rw,
|
@{sys}/devices/pci[0-9]*/**/{ata,usb,mmc}[0-9]/{,**/}remove rw,
|
||||||
@ -124,6 +126,7 @@ profile udisksd @{exec_path} flags=(attach_disconnected) {
|
|||||||
@{run}/udisks2/ rw,
|
@{run}/udisks2/ rw,
|
||||||
@{run}/udisks2/loop{,.*} rw,
|
@{run}/udisks2/loop{,.*} rw,
|
||||||
@{run}/udisks2/unlocked-luks{,.*} rw,
|
@{run}/udisks2/unlocked-luks{,.*} rw,
|
||||||
|
@{run}/udisks2/unlocked-crypto-dev{,.*} rw,
|
||||||
@{run}/udisks2/mounted-fs{,.*} rw,
|
@{run}/udisks2/mounted-fs{,.*} rw,
|
||||||
|
|
||||||
@{run}/systemd/seats/seat[0-9]* r,
|
@{run}/systemd/seats/seat[0-9]* r,
|
||||||
|
Loading…
Reference in New Issue
Block a user