mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2025-01-31 23:35:03 +01:00
30 lines
1 KiB
Text
30 lines
1 KiB
Text
# apparmor.d - Full set of apparmor profiles
|
|
# Copyright (C) 2019-2022 Mikhail Morfikov
|
|
# Copyright (C) 2021-2022 Alexandre Pujol <alexandre@pujol.io>
|
|
# SPDX-License-Identifier: GPL-2.0-only
|
|
|
|
abi <abi/3.0>,
|
|
|
|
@{etc_ro}/default/nss r,
|
|
@{etc_ro}/gai.conf r,
|
|
@{etc_ro}/group r,
|
|
@{etc_ro}/host.conf r,
|
|
@{etc_ro}/hosts r,
|
|
@{etc_ro}/nsswitch.conf r,
|
|
@{etc_ro}/passwd r,
|
|
@{etc_ro}/protocols r,
|
|
@{etc_ro}/resolv.conf r,
|
|
@{etc_ro}/services r,
|
|
|
|
@{run}/systemd/resolve/stub-resolv.conf r,
|
|
|
|
# NSS records from systemd-userdbd.service
|
|
@{run}/systemd/userdb/ r,
|
|
@{run}/systemd/userdb/io.systemd.DynamicUser rw, # systemd-exec users
|
|
@{run}/systemd/userdb/io.systemd.Home rw, # systemd-home dirs
|
|
@{run}/systemd/userdb/io.systemd.Machine rw, # systemd-machined
|
|
@{run}/systemd/userdb/io.systemd.Multiplexer rw,
|
|
@{run}/systemd/userdb/io.systemd.NameServiceSwitch rw, # UNIX/glibc NSS
|
|
@{PROC}/sys/kernel/random/boot_id r,
|
|
|
|
include if exists <abstractions/nameservice-strict.d>
|