apparmor/profiles/extras/usr.sbin.squid

65 lines
1.6 KiB
Text

# $Id$
# ------------------------------------------------------------------
#
# Copyright (C) 2002-2006 Novell/SUSE
#
# This program is free software; you can redistribute it and/or
# modify it under the terms of version 2 of the GNU General Public
# License published by the Free Software Foundation.
#
# ------------------------------------------------------------------
# vim:syntax=apparmor
#include <tunables/global>
/usr/sbin/squid {
#include <abstractions/base>
#include <abstractions/consoles>
#include <abstractions/kerberosclient>
#include <abstractions/nameservice>
capability setgid,
capability setuid,
/usr/lib/squid/* rix,
/usr/sbin/squid rix,
/usr/sbin/unlinkd ixr,
/var/cache/squid/** lrw,
/dev/tty rw,
/etc/mtab r,
/etc/squid/* r,
/proc/*/mounts r,
/proc/mounts r,
/usr/share/squid/** r,
/var/log/squid/access.log w,
/proc/sys/kernel/ngroups_max r,
/var/log/squid/cache.log rw,
/var/log/squid/store.log w,
/var/run/squid.pid lrw,
/usr/sbin/digest_pw_auth rix,
/usr/sbin/diskd rix,
/usr/sbin/getpwname_auth rix,
/usr/sbin/ip_user_check rix,
/usr/sbin/msnt_auth rix,
/usr/sbin/ncsa_auth rix,
/usr/sbin/no_check.pl rix,
/usr/sbin/ntlm_auth rix,
/usr/sbin/pam_auth rix,
/usr/sbin/rcsquid rix,
/usr/sbin/smb_auth rix,
/usr/sbin/smb_auth.pl rix,
/usr/sbin/smb_auth.sh rix,
/usr/sbin/squid rix,
/usr/sbin/squid_ldap_auth rix,
/usr/sbin/squid_ldap_group rix,
/usr/sbin/squid_ldapauth rix,
/usr/sbin/squid_unix_group rix,
/usr/sbin/squidclient rix,
/usr/sbin/unlinkd rix,
/usr/sbin/wbinfo_group.pl rix,
/usr/sbin/yp_auth rix,
}