mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2024-11-15 07:54:17 +01:00
Use nameservice-strict, fix exec
This commit is contained in:
parent
e2e14510ff
commit
ddf5f1f512
@ -10,6 +10,7 @@ include <tunables/global>
|
||||
profile zsysctl @{exec_path} flags=(complain) {
|
||||
include <abstractions/base>
|
||||
include <abstractions/dbus-strict>
|
||||
include <abstractions/nameservice-strict>
|
||||
|
||||
capability sys_ptrace,
|
||||
capability sys_admin,
|
||||
@ -18,13 +19,9 @@ profile zsysctl @{exec_path} flags=(complain) {
|
||||
interface=org.freedesktop.PolicyKit1.Authority
|
||||
member=CheckAuthorization,
|
||||
|
||||
@{exec_path} rm,
|
||||
/{usr/,}bin/zsysctl rix,
|
||||
/{usr/,}bin/zsysd rix,
|
||||
@{exec_path} rmix,
|
||||
|
||||
/etc/hostid r,
|
||||
/etc/passwd r,
|
||||
/etc/nsswitch.conf r,
|
||||
/etc/zsys.conf r,
|
||||
|
||||
/var/log/unattended-upgrades/unattended-upgrades-dpkg.log rw,
|
||||
|
Loading…
Reference in New Issue
Block a user