mirror of
https://gitlab.com/apparmor/apparmor.git
synced 2025-03-04 08:24:42 +01:00
This patch adds a variable definition for the location of /proc in
tunables/proc and modifies all users of /proc to use the variable instead. I also converted some uses of /proc/*/ to /proc/[0-9]*/ to be a little more restrictive, as well as removing some references to proc files that are already covered by abstractions/base (the removals in abstractions/bash seem justified as all uses of abstractions/bash are immediately preceded by abstractions/base).
This commit is contained in:
parent
f442a50a4d
commit
7e6e37953f
53 changed files with 70 additions and 134 deletions
|
@ -34,7 +34,7 @@
|
|||
/dev/snd/* rw,
|
||||
/dev/sound/* rw,
|
||||
|
||||
/proc/asound/** rw,
|
||||
@{PROC}/asound/** rw,
|
||||
|
||||
/usr/share/alsa/** r,
|
||||
|
||||
|
|
|
@ -65,12 +65,12 @@
|
|||
/dev/full rw,
|
||||
|
||||
# Sometimes used to determine kernel/user interfaces to use
|
||||
/proc/sys/kernel/version r,
|
||||
@{PROC}/sys/kernel/version r,
|
||||
# Depending on which glibc routine uses this file, base may not be the
|
||||
# best place -- but many profiles require it, and it is quite harmless.
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
@{PROC}/sys/kernel/ngroups_max r,
|
||||
|
||||
# glibc's sysconf(3) routine to determine free memory, etc
|
||||
/proc/meminfo r,
|
||||
/proc/stat r,
|
||||
/proc/cpuinfo r,
|
||||
@{PROC}/meminfo r,
|
||||
@{PROC}/stat r,
|
||||
@{PROC}/cpuinfo r,
|
||||
|
|
|
@ -33,12 +33,8 @@
|
|||
|
||||
# bash inspects filesystems at startup
|
||||
/etc/mtab r,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
/proc/*/mounts r,
|
||||
/proc/filesystems r,
|
||||
|
||||
# bash wants, not sure why.
|
||||
/proc/meminfo r,
|
||||
@{PROC}/[0-9]*/mounts r,
|
||||
@{PROC}/filesystems r,
|
||||
|
||||
# probably readline wants to know terminal capabilities
|
||||
/usr/share/terminfo/** r,
|
||||
|
|
|
@ -17,7 +17,7 @@
|
|||
|
||||
/etc/postfix/*.cf r,
|
||||
/etc/postfix/*.db r,
|
||||
/proc/net/if_inet6 r,
|
||||
@{PROC}/net/if_inet6 r,
|
||||
/usr/lib/postfix/*.so mr,
|
||||
/usr/lib64/sasl2/* mr,
|
||||
/usr/lib64/sasl2/ r,
|
||||
|
|
|
@ -17,7 +17,7 @@
|
|||
capability sys_admin,
|
||||
|
||||
/boot/System.map* r,
|
||||
/proc/kmsg r,
|
||||
@{PROC}/kmsg r,
|
||||
/sbin/klogd rmix,
|
||||
/var/log/boot.msg rwl,
|
||||
/var/run/klogd.pid rwl,
|
||||
|
|
|
@ -13,3 +13,4 @@
|
|||
# should be included here
|
||||
|
||||
#include <tunables/home>
|
||||
#include <tunables/proc>
|
||||
|
|
|
@ -21,7 +21,7 @@
|
|||
/etc/identd.key r,
|
||||
/etc/identd.pid w,
|
||||
/usr/sbin/identd rmix,
|
||||
/proc/net/tcp r,
|
||||
/proc/net/tcp6 r,
|
||||
@{PROC}/net/tcp r,
|
||||
@{PROC}/net/tcp6 r,
|
||||
/var/run/identd.pid w,
|
||||
}
|
||||
|
|
|
@ -25,9 +25,8 @@
|
|||
|
||||
/usr/sbin/mdnsd rmix,
|
||||
|
||||
/proc/net/ r,
|
||||
/proc/net/unix r,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
@{PROC}/net/ r,
|
||||
@{PROC}/net/unix r,
|
||||
/var/run/mdnsd lw,
|
||||
/var/run/mdnsd.pid w,
|
||||
}
|
||||
|
|
|
@ -21,13 +21,11 @@
|
|||
capability net_bind_service,
|
||||
|
||||
/etc/nscd.conf r,
|
||||
/proc/meminfo r,
|
||||
/proc/*/fd/ r,
|
||||
/proc/*/fd/* r,
|
||||
/proc/*/maps r,
|
||||
/proc/*/mounts r,
|
||||
/proc/filesystems r,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
@{PROC}/[0-9]*/fd/ r,
|
||||
@{PROC}/[0-9]*/fd/* r,
|
||||
@{PROC}/[0-9]*/maps r,
|
||||
@{PROC}/[0-9]*/mounts r,
|
||||
@{PROC}/filesystems r,
|
||||
/usr/sbin/nscd rmix,
|
||||
/var/run/.nscd_socket wl,
|
||||
/var/run/nscd/ r,
|
||||
|
|
|
@ -33,7 +33,7 @@
|
|||
/etc/ntp/drift* rwl,
|
||||
/etc/ntp/keys r,
|
||||
/etc/ntp/step-tickers r,
|
||||
/proc/net/if_inet6 r,
|
||||
@{PROC}/net/if_inet6 r,
|
||||
/tmp/ntp* rwl,
|
||||
/usr/sbin/ntpd rmix,
|
||||
/var/lib/ntp/etc/ntp.conf.iburst r,
|
||||
|
|
|
@ -18,6 +18,6 @@
|
|||
|
||||
capability net_raw,
|
||||
|
||||
/proc/net/route r,
|
||||
@{PROC}/net/route r,
|
||||
/usr/sbin/traceroute rmix,
|
||||
}
|
||||
|
|
|
@ -25,9 +25,9 @@
|
|||
|
||||
/bin/netstat rmix,
|
||||
/etc/networks r,
|
||||
/proc r,
|
||||
/proc/[0-9]*/cmdline r,
|
||||
/proc/[0-9]*/fd r,
|
||||
/proc/net r,
|
||||
/proc/net/* r,
|
||||
@{PROC} r,
|
||||
@{PROC}/[0-9]*/cmdline r,
|
||||
@{PROC}/[0-9]*/fd r,
|
||||
@{PROC}/net r,
|
||||
@{PROC}/net/* r,
|
||||
}
|
||||
|
|
|
@ -40,8 +40,8 @@
|
|||
/etc/logrotate.d r,
|
||||
/etc/logrotate.d/* r,
|
||||
/etc/subdomain.d r,
|
||||
/proc r,
|
||||
/proc/[1-9]* r,
|
||||
@{PROC} r,
|
||||
@{PROC}/[1-9]* r,
|
||||
/tmp w,
|
||||
/tmp/file* wl,
|
||||
/tmp/logrot* wlr,
|
||||
|
|
|
@ -21,7 +21,6 @@
|
|||
/dev/tty wr ,
|
||||
/etc/cron.daily/slocate.cron r ,
|
||||
/etc/mtab r ,
|
||||
/proc/meminfo r ,
|
||||
/usr/bin/slocate mixr,
|
||||
/usr/bin/renice mixr,
|
||||
/** r ,
|
||||
|
|
|
@ -132,11 +132,9 @@
|
|||
/opt/mozilla/bin/mozilla.sh Pxr,
|
||||
/opt/mozilla/lib/** r,
|
||||
/opt/mozilla/lib/**.so mr,
|
||||
/proc/*/cmdline r,
|
||||
/proc/meminfo r,
|
||||
/proc/net r,
|
||||
/proc/net/* r,
|
||||
/proc/stat r,
|
||||
@{PROC}/*/cmdline r,
|
||||
@{PROC}/net r,
|
||||
@{PROC}/net/* r,
|
||||
/tmp r,
|
||||
/tmp/* lrw,
|
||||
/tmp/.ICE-unix/* w,
|
||||
|
|
|
@ -59,9 +59,7 @@
|
|||
/opt/kde3/bin/kde-config mixr,
|
||||
/opt/mozilla/lib/lib*so* mr,
|
||||
/opt/mozilla/lib64/lib*so* mr,
|
||||
/proc/cpuinfo r,
|
||||
/proc/stat r,
|
||||
/proc/*/cmdline r,
|
||||
@{PROC}/*/cmdline r,
|
||||
/usr/X11R6/lib/Acrobat*/Resource/Font/* r,
|
||||
/usr/X11R6/lib/Acrobat*/Resource/Font/PFM/* r,
|
||||
/usr/X11R6/lib/lib*so* mr,
|
||||
|
|
|
@ -37,8 +37,6 @@
|
|||
/opt/gnome/lib/gnome-vfs** mr,
|
||||
/opt/gnome/lib/lib*so* mr,
|
||||
/opt/gnome/share/evolution-data-server-*/** mr,
|
||||
/proc/meminfo r,
|
||||
/proc/stat r,
|
||||
/usr/X11R6/lib/X11/locale/* r,
|
||||
|
||||
}
|
||||
|
|
|
@ -33,12 +33,12 @@
|
|||
/bin/ps mixr,
|
||||
/dev/random r,
|
||||
/etc/dhclient.conf r,
|
||||
/proc/ r,
|
||||
/proc/interrupts r,
|
||||
/proc/net/dev r,
|
||||
/proc/rtc r,
|
||||
/proc/self/status r,
|
||||
/proc/stat r,
|
||||
@{PROC}/ r,
|
||||
@{PROC}/interrupts r,
|
||||
@{PROC}/net/dev r,
|
||||
@{PROC}/rtc r,
|
||||
# following rule shouldn't work, self is a symlink
|
||||
@{PROC}/self/status r,
|
||||
/sbin/arp rmix,
|
||||
/usr/bin/dig rmix,
|
||||
/usr/bin/uptime rmix,
|
||||
|
|
|
@ -19,7 +19,6 @@
|
|||
/dev/tty wr,
|
||||
/etc/X11/fs/config r,
|
||||
/etc/mtab r,
|
||||
/proc/meminfo r,
|
||||
/tmp/.font-unix/fs710[0-9] wl,
|
||||
/usr/X11R6/bin/xfs rmix,
|
||||
/usr/X11R6/lib/lib*.so* mr,
|
||||
|
|
|
@ -20,7 +20,6 @@
|
|||
capability setgid,
|
||||
capability setuid,
|
||||
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
/usr/lib/man-db/man Px,
|
||||
|
||||
}
|
||||
|
|
|
@ -37,10 +37,9 @@
|
|||
/etc/opera6rc rw,
|
||||
/etc/opera6rc.fixed rw,
|
||||
/opt r,
|
||||
/proc/*/stat r,
|
||||
/proc/net/if_inet6 r,
|
||||
/proc/stat r,
|
||||
/proc/sys/vm/heap-stack-gap r,
|
||||
@{PROC}/[0-9]*/stat r,
|
||||
@{PROC}/net/if_inet6 r,
|
||||
@{PROC}/sys/vm/heap-stack-gap r,
|
||||
|
||||
@{HOME}/.fonts.cache-* r,
|
||||
@{HOME}/.fonts r,
|
||||
|
|
|
@ -63,12 +63,11 @@
|
|||
/opt/kde3/bin/kde-config mixr,
|
||||
/opt/kde3/share/applications/**.desktop r,
|
||||
/opt/kde3/share/applications/mimeinfo.cache r,
|
||||
/proc/*/cmdline r,
|
||||
/proc/*/maps r,
|
||||
/proc/*/stat r,
|
||||
/proc/net/if_inet6 r,
|
||||
/proc/stat r,
|
||||
/proc/sys/vm/heap-stack-gap r,
|
||||
@{PROC}/[0-9]*/cmdline r,
|
||||
@{PROC}/[0-9]*/maps r,
|
||||
@{PROC}/[0-9]*/stat r,
|
||||
@{PROC}/net/if_inet6 r,
|
||||
@{PROC}/sys/vm/heap-stack-gap r,
|
||||
/usr/X11R6/lib/Acrobat*/Browser/intellinux/nppdf.so mr,
|
||||
/usr/X11R6/lib/Acrobat*/Resource/Font/** r,
|
||||
/usr/X11R6/lib/lib*so* mr,
|
||||
|
|
|
@ -33,7 +33,6 @@
|
|||
/etc/papersize r,
|
||||
/etc/termcap r,
|
||||
/opt/gnome/man/** r,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
/usr/bin/apropos Px,
|
||||
/usr/bin/cmp rmix,
|
||||
/usr/bin/groff rmix,
|
||||
|
|
|
@ -25,6 +25,5 @@
|
|||
/etc/postfix/main.cf r,
|
||||
/{var/spool/postfix/,}private/anvil rw,
|
||||
/{var/spool/postfix/,}pid/unix.anvil rw,
|
||||
/proc/net/if_inet6 r,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
@{PROC}/net/if_inet6 r,
|
||||
}
|
||||
|
|
|
@ -43,6 +43,5 @@
|
|||
/{var/spool/postfix/,}pid/unix.trace rw,
|
||||
|
||||
/etc/postfix/main.cf r,
|
||||
/proc/net/if_inet6 r,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
@{PROC}/net/if_inet6 r,
|
||||
}
|
||||
|
|
|
@ -31,6 +31,4 @@
|
|||
/{var/spool/postfix/,}pid/unix.cleanup rw,
|
||||
/etc/{m,fs}tab r,
|
||||
/etc/postfix/* r,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
/proc/{stat,cpuinfo} r,
|
||||
}
|
||||
|
|
|
@ -48,7 +48,4 @@
|
|||
|
||||
@{HOME}/.forward r,
|
||||
|
||||
/proc/stat r,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
|
||||
}
|
||||
|
|
|
@ -33,7 +33,6 @@
|
|||
/etc/{postfix/,}aliases.db r,
|
||||
# mailman on SuSE is configed to have its own alias file
|
||||
/var/lib/mailman/data/aliases.db r,
|
||||
/proc/{cpuinfo,stat} r,
|
||||
/{var/spool/postfix/,}active/[0-9A-F]/[0-9A-F]/* rw,
|
||||
/{var/spool/postfix/,}active/[0-9A-F]/[0-9A-F]* rw,
|
||||
/{var/spool/postfix/,}active/[0-9A-F]* rw,
|
||||
|
|
|
@ -19,8 +19,6 @@
|
|||
|
||||
/usr/lib/postfix/pickup rmix,
|
||||
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
|
||||
/{var/spool/postfix/,}public/cleanup w,
|
||||
/{var/spool/postfix/,}public/pickup r,
|
||||
/{var/spool/postfix/,}maildrop r,
|
||||
|
|
|
@ -22,6 +22,5 @@
|
|||
/usr/lib/postfix/proxymap rmix,
|
||||
|
||||
/etc/postfix/main.cf r,
|
||||
/proc/net/if_inet6 r,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
@{PROC}/net/if_inet6 r,
|
||||
}
|
||||
|
|
|
@ -18,7 +18,6 @@
|
|||
#include <program-chunks/postfix-common>
|
||||
|
||||
/usr/lib/postfix/qmgr rmix,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
/{var/spool/postfix/,}active r,
|
||||
/{var/spool/postfix/,}active/[0-9A-F] r,
|
||||
/{var/spool/postfix/,}active/[0-9A-F]/[0-9A-F] rwl,
|
||||
|
|
|
@ -19,6 +19,5 @@
|
|||
|
||||
/usr/lib/postfix/scache rmix,
|
||||
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
/var/run/nscd/group r,
|
||||
}
|
||||
|
|
|
@ -52,6 +52,4 @@
|
|||
/{var/spool/postfix/,}maildrop r,
|
||||
/{var/spool/postfix/,}maildrop/[0-9A-F]* r,
|
||||
/{var/spool/postfix/,}pid/unix.showq rw,
|
||||
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
}
|
||||
|
|
|
@ -38,12 +38,9 @@
|
|||
/{var/spool/postfix/,}pid/unix.relay rw,
|
||||
/etc/postfix/{ssl/,}*.pem r,
|
||||
/etc/postfix/prng_exch rw,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
/usr/share/ssl/certs/ca-bundle.crt r,
|
||||
/usr/share/ssl/openssl.cnf r,
|
||||
/etc/postfix/virtual.db r,
|
||||
/etc/postfix/sasl_passwd.db r,
|
||||
/etc/mtab r,
|
||||
/proc/stat r,
|
||||
/proc/meminfo r,
|
||||
}
|
||||
|
|
|
@ -55,9 +55,5 @@
|
|||
|
||||
/var/run/sasl2/mux w,
|
||||
|
||||
/proc/net/if_inet6 r,
|
||||
/proc/cpuinfo r,
|
||||
/proc/stat r,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
|
||||
@{PROC}/net/if_inet6 r,
|
||||
}
|
||||
|
|
|
@ -20,7 +20,6 @@
|
|||
/usr/lib/postfix/tlsmgr rmix,
|
||||
|
||||
/etc/postfix/prng_exch rw,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
/{var/spool/postfix/,}private/tlsmgr r,
|
||||
/var/run/__db.smtpd_tls_session_cache.db rw,
|
||||
/var/run/smtpd_tls_session_cache.db rw,
|
||||
|
|
|
@ -24,7 +24,4 @@
|
|||
/etc/postfix/virtual.db r,
|
||||
/etc/{m,fs}tab r,
|
||||
/var/spool/postfix/pid/unix.rewrite rw,
|
||||
|
||||
/proc/{cpuinfo,stat} r,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
}
|
||||
|
|
|
@ -40,8 +40,6 @@
|
|||
/etc/php.d r,
|
||||
/etc/php.d/** r,
|
||||
/etc/php.ini r,
|
||||
/proc/meminfo r,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
/tmp/auth_ldap_cache.sem wl,
|
||||
/tmp/session_mm_apache0.sem wl,
|
||||
/tmp/session_mm_apache2handler0.sem wl,
|
||||
|
|
|
@ -27,8 +27,6 @@
|
|||
capability setgid,
|
||||
capability setuid,
|
||||
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
|
||||
/etc/lighttpd r,
|
||||
/etc/lighttpd/*.conf r,
|
||||
/etc/lighttpd/conf.d/*.conf r,
|
||||
|
|
|
@ -22,8 +22,8 @@
|
|||
|
||||
/etc/oidentd.conf r,
|
||||
/etc/oidentd_masq.conf r,
|
||||
/proc/net/tcp r,
|
||||
/proc/net/tcp6 r,
|
||||
@{PROC}/net/tcp r,
|
||||
@{PROC}/net/tcp6 r,
|
||||
|
||||
# spoofing feature of oidentd
|
||||
@{HOME}/.ispoof r,
|
||||
|
|
|
@ -26,9 +26,7 @@
|
|||
/etc/postfix/__db.aliases.db lrw,
|
||||
/etc/__db.aliases.db rwl,
|
||||
/usr/sbin/postalias rmix,
|
||||
/proc/net/if_inet6 r,
|
||||
/proc/cpuinfo r,
|
||||
/proc/stat r,
|
||||
@{PROC}/net/if_inet6 r,
|
||||
# On SuSE, mailman is configured to use its own alias db
|
||||
/var/lib/mailman/data/aliases r,
|
||||
/var/lib/mailman/data/__db.aliases.db rwl,
|
||||
|
|
|
@ -25,7 +25,7 @@
|
|||
/etc/postfix r,
|
||||
/etc/postfix/main.cf r,
|
||||
/etc/postfix/postfix-script mixr,
|
||||
/proc/net/if_inet6 r,
|
||||
@{PROC}/net/if_inet6 r,
|
||||
/usr/sbin/postdrop rmix,
|
||||
/var/spool/postfix r,
|
||||
/var/spool/postfix/maildrop r,
|
||||
|
|
|
@ -21,8 +21,6 @@
|
|||
/etc/mtab r,
|
||||
/etc/postfix/* r,
|
||||
/etc/postfix/*.db rwl,
|
||||
/proc/cpuinfo r,
|
||||
/proc/net/if_inet6 r,
|
||||
/proc/stat r,
|
||||
@{PROC}/net/if_inet6 r,
|
||||
/usr/sbin/postmap rmix,
|
||||
}
|
||||
|
|
|
@ -44,11 +44,8 @@
|
|||
/etc/sendmail.cf r,
|
||||
/etc/sendmail.cw r,
|
||||
/etc/shells r,
|
||||
/proc/cpuinfo r,
|
||||
/proc/loadavg r,
|
||||
/proc/meminfo r,
|
||||
/proc/net/if_inet6 r,
|
||||
/proc/stat r,
|
||||
@{PROC}/loadavg r,
|
||||
@{PROC}/net/if_inet6 r,
|
||||
/root/dead.letter w,
|
||||
/root/.forward rw,
|
||||
/usr/kerberos/lib/lib*.so* mr,
|
||||
|
|
|
@ -25,8 +25,7 @@
|
|||
/etc/postfix/aliases.db rw,
|
||||
/etc/postfix/main.cf r,
|
||||
/etc/postfix/postfix-script Px,
|
||||
/proc/meminfo r,
|
||||
/proc/net/if_inet6 r,
|
||||
@{PROC}/net/if_inet6 r,
|
||||
/usr/lib/postfix r,
|
||||
/usr/lib/postfix/master Px,
|
||||
/usr/lib/postfix/showq Px,
|
||||
|
|
|
@ -15,8 +15,7 @@
|
|||
#include <abstractions/base>
|
||||
#include <abstractions/nameservice>
|
||||
|
||||
/proc/loadavg r,
|
||||
/proc/cpuinfo r,
|
||||
@{PROC}/loadavg r,
|
||||
/etc/aliases rw,
|
||||
/etc/aliases.db rw,
|
||||
/etc/fstab r,
|
||||
|
@ -29,7 +28,6 @@
|
|||
/etc/sendmail.cf r,
|
||||
/etc/sendmail.cw r,
|
||||
/etc/shells r,
|
||||
/proc/stat r,
|
||||
/root/.forward rw,
|
||||
/root/dead.letter w,
|
||||
/usr/bin/procmail Px,
|
||||
|
|
|
@ -32,7 +32,7 @@
|
|||
@{HOME}/** rwl,
|
||||
@{HOMEDIRS} rwl,
|
||||
|
||||
/proc/*/mounts r,
|
||||
@{PROC}/[0-9]*/mounts r,
|
||||
/tmp rw,
|
||||
/var/tmp rw,
|
||||
/var/tmp/** lrw,
|
||||
|
|
|
@ -30,7 +30,6 @@
|
|||
|
||||
@{HOME}/.spamassassin/* lrw,
|
||||
|
||||
/proc/stat r,
|
||||
/tmp/spamd-*-init r,
|
||||
/tmp/spamd-*-init/** lrw,
|
||||
/usr/bin/perl mix,
|
||||
|
|
|
@ -30,11 +30,10 @@
|
|||
/dev/tty rw,
|
||||
/etc/mtab r,
|
||||
/etc/squid/* r,
|
||||
/proc/*/mounts r,
|
||||
/proc/mounts r,
|
||||
@{PROC}/[0-9]*/mounts r,
|
||||
@{PROC}/mounts r,
|
||||
/usr/share/squid/** r,
|
||||
/var/log/squid/access.log w,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
/var/log/squid/cache.log rw,
|
||||
/var/log/squid/store.log w,
|
||||
/var/run/squid.pid lrw,
|
||||
|
|
|
@ -42,8 +42,8 @@
|
|||
/var/run w,
|
||||
/var/run/sshd{,.init}.pid wl,
|
||||
|
||||
/proc/[0-9]*/fd/ r,
|
||||
/proc/[0-9]*/loginuid w,
|
||||
@{PROC}/[0-9]*/fd/ r,
|
||||
@{PROC}/[0-9]*/loginuid w,
|
||||
|
||||
# should only be here for use in non-change-hat openssh
|
||||
# duplicated from EXEC hat
|
||||
|
@ -67,8 +67,7 @@
|
|||
|
||||
/dev/pts/[0-9]* rw,
|
||||
/etc/ssh/moduli r,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
/proc/[0-9]*/mounts r,
|
||||
@{PROC}/[0-9]*/mounts r,
|
||||
|
||||
# duplicated from AUTHENTICATED
|
||||
/etc/motd r,
|
||||
|
@ -134,8 +133,7 @@
|
|||
/etc/hosts.allow r,
|
||||
/etc/hosts.deny r,
|
||||
/etc/ssh/moduli r,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
/proc/[0-9]*/mounts r,
|
||||
@{PROC}/[0-9]*/mounts r,
|
||||
|
||||
# for debugging
|
||||
# /dev/pts/[0-9]* rw,
|
||||
|
@ -160,7 +158,6 @@
|
|||
/etc/localtime r,
|
||||
/etc/login.defs r,
|
||||
/etc/motd r,
|
||||
/proc/sys/kernel/ngroups_max r,
|
||||
/tmp/ssh-*/agent.[0-9]* rwl,
|
||||
/tmp/ssh-*[0-9]*/ w,
|
||||
|
||||
|
|
|
@ -38,8 +38,8 @@
|
|||
/etc/skel r,
|
||||
/etc/skel/** r,
|
||||
@{HOMEDIRS}** rw,
|
||||
/proc/*/mounts r,
|
||||
/proc/filesystems r,
|
||||
@{PROC}/[0-9]*/mounts r,
|
||||
@{PROC}/filesystems r,
|
||||
/usr/lib*/pwdutils/*so* mr,
|
||||
/usr/sbin/adduser rmix,
|
||||
/usr/sbin/useradd rmix,
|
||||
|
|
|
@ -38,7 +38,7 @@
|
|||
/etc/shadow* rwl,
|
||||
/etc/pwdutils/logging r,
|
||||
@{HOMEDIRS}** rwl,
|
||||
/proc/*/mounts r,
|
||||
@{PROC}/[0-9]*/mounts r,
|
||||
/usr/bin/crontab rmix,
|
||||
/usr/lib*/pwdutils/*.so.* mr,
|
||||
/usr/sbin/userdel rmix,
|
||||
|
|
|
@ -24,7 +24,6 @@
|
|||
/etc/shells r,
|
||||
/etc/vsftpd.* r,
|
||||
/etc/vsftpd/* r,
|
||||
/proc/meminfo r,
|
||||
/usr/sbin/vsftpd rmix,
|
||||
/var/log/vsftpd.log w,
|
||||
/var/log/xferlog w,
|
||||
|
|
Loading…
Add table
Reference in a new issue