mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2025-01-18 00:48:10 +01:00
update
This commit is contained in:
parent
b5cdd0af44
commit
ceb60bde82
1 changed files with 3 additions and 5 deletions
|
@ -19,6 +19,9 @@ profile su @{exec_path} {
|
|||
capability setgid,
|
||||
capability setuid,
|
||||
capability dac_read_search,
|
||||
capability sys_resource,
|
||||
# No clear purpose, deny until needed
|
||||
deny capability net_admin,
|
||||
#audit deny capability net_bind_service,
|
||||
|
||||
signal (send) set=(term,kill),
|
||||
|
@ -51,11 +54,6 @@ profile su @{exec_path} {
|
|||
@{PROC}/cmdline r,
|
||||
@{sys}/devices/virtual/tty/console/active r,
|
||||
|
||||
# Upstreaming
|
||||
capability sys_resource,
|
||||
# No clear purpose, deny until needed
|
||||
deny capability net_admin,
|
||||
|
||||
# pseudo-terminal
|
||||
capability chown,
|
||||
|
||||
|
|
Loading…
Reference in a new issue