apparmor/profiles
nl6720 089064439d
profiles/apparmor.d/abstractions/samba: allow modifying /var/cache/samba/*.tdb
samba-dcerpcd requires access to `/var/cache/samba/names.tdb`.

    audit: type=1400 audit(1676835286.187:62): apparmor="DENIED" operation="open" profile="samba-dcerpcd" name="/var/cache/samba/names.tdb" pid=6948 comm="samba-dcerpcd" requested_mask="wrc" denied_mask="wrc" fsuid=0 ouid=0

See also https://bbs.archlinux.org/viewtopic.php?id=281411

Since `usr.sbin.winbindd` already has a rule for it, and `usr.sbin.nmbd`
has similar ones, simply add `/var/cache/samba/*.tdb rwk` to
`abstractions/samba`.

(cherry picked from commit 763c4ecd23,
with cleanup of now-superfluous rules in usr.sbin.nmbd and
usr.sbin.winbindd dropped)
2023-02-27 20:36:30 +01:00
..
apparmor/profiles/extras Merge postfix-tlsmgr: allow reading openssl.cnf 2023-02-09 00:17:43 -08:00
apparmor.d profiles/apparmor.d/abstractions/samba: allow modifying /var/cache/samba/*.tdb 2023-02-27 20:36:30 +01:00
Makefile Use basepath.py in profiles Makefile 2022-08-03 10:56:51 +02:00