mirror of
https://gitlab.com/apparmor/apparmor.git
synced 2025-03-04 16:35:02 +01:00

Begin preparing policy for the 4.0 release. This may result in new denials. This is expected and needed to make sure policy is ready for the 4.0 release. Signed-off-by: John Johansen <john.johansen@canonical.com>
40 lines
947 B
Text
40 lines
947 B
Text
# Last Modified: Tue Jan 3 00:17:40 2012
|
|
|
|
abi <abi/4.0>,
|
|
|
|
include <tunables/global>
|
|
|
|
profile smbldap-useradd /usr/{bin,sbin}/smbldap-useradd {
|
|
include <abstractions/base>
|
|
include <abstractions/bash>
|
|
include <abstractions/nameservice>
|
|
include <abstractions/perl>
|
|
|
|
/dev/tty rw,
|
|
/{,usr/}bin/bash ix,
|
|
/etc/init.d/nscd Cx,
|
|
/etc/shadow r,
|
|
/etc/smbldap-tools/smbldap.conf r,
|
|
/etc/smbldap-tools/smbldap_bind.conf r,
|
|
/usr/{bin,sbin}/smbldap-useradd r,
|
|
/usr/{bin,sbin}/smbldap_tools.pm r,
|
|
/var/log/samba/log.smbd w,
|
|
|
|
# Site-specific additions and overrides. See local/README for details.
|
|
include if exists <local/usr.sbin.smbldap-useradd>
|
|
|
|
profile /etc/init.d/nscd {
|
|
include <abstractions/base>
|
|
include <abstractions/nameservice>
|
|
|
|
capability sys_ptrace,
|
|
|
|
/{,usr/}bin/bash r,
|
|
/{,usr/}bin/mountpoint rix,
|
|
/{,usr/}bin/systemctl rix,
|
|
/dev/tty rw,
|
|
/etc/init.d/nscd r,
|
|
/etc/rc.status r,
|
|
|
|
}
|
|
}
|