This commit is contained in:
nobodysu 2022-02-20 02:29:31 +03:00
parent b5cdd0af44
commit ceb60bde82

View file

@ -19,6 +19,9 @@ profile su @{exec_path} {
capability setgid,
capability setuid,
capability dac_read_search,
capability sys_resource,
# No clear purpose, deny until needed
deny capability net_admin,
#audit deny capability net_bind_service,
signal (send) set=(term,kill),
@ -51,11 +54,6 @@ profile su @{exec_path} {
@{PROC}/cmdline r,
@{sys}/devices/virtual/tty/console/active r,
# Upstreaming
capability sys_resource,
# No clear purpose, deny until needed
deny capability net_admin,
# pseudo-terminal
capability chown,