mirror of
https://gitlab.com/apparmor/apparmor
synced 2025-08-30 22:05:27 +00:00
Update usr.sbin.winbindd profile
Winbind requires access to /var/cache/samba/msg.lock/*. Move msg.lock/ to abstractions/samba. On Arch Linux Winbind's pid is set to /run/winbindd.pid. Signed-off-by: nl6720 <nl6720@gmail.com>
This commit is contained in:
@@ -22,6 +22,8 @@
|
||||
/var/log/samba/* w,
|
||||
/{,var/}run/samba/ w,
|
||||
/{,var/}run/samba/*.tdb rw,
|
||||
/{{var/,}run,var/cache}/samba/msg.lock/ rwk,
|
||||
/{{var/,}run,var/cache}/samba/msg.lock/[0-9]* rwk,
|
||||
|
||||
# required for clustering
|
||||
/var/lib/ctdb/** rwk,
|
||||
|
@@ -24,7 +24,6 @@ profile nmbd /usr/{bin,sbin}/nmbd {
|
||||
/var/{cache,lib}/samba/unexpected rw,
|
||||
/var/cache/samba/msg/ rw,
|
||||
/var/cache/samba/msg/* w,
|
||||
/var/cache/samba/msg.lock/{,*} rwk,
|
||||
|
||||
/{,var/}run/nmbd.pid rwk,
|
||||
/{,var/}run/samba/** rwk,
|
||||
|
@@ -49,8 +49,6 @@ profile smbd /usr/{bin,sbin}/smbd {
|
||||
/{,var/}run/samba/ncalrpc/ rw,
|
||||
/{,var/}run/samba/ncalrpc/** rw,
|
||||
/{,var/}run/samba/smbd.pid rw,
|
||||
/{,var/}run/samba/msg.lock/ rw,
|
||||
/{,var/}run/samba/msg.lock/[0-9]* rwk,
|
||||
/var/spool/samba/** rw,
|
||||
|
||||
@{HOMEDIRS}/** lrwk,
|
||||
|
@@ -28,7 +28,7 @@ profile winbindd /usr/{bin,sbin}/winbindd {
|
||||
/var/cache/krb5rcache/* rw,
|
||||
/var/cache/samba/*.tdb rwk,
|
||||
/var/log/samba/log.winbindd rw,
|
||||
/{var/,}run/samba/winbindd.pid rwk,
|
||||
/{var/,}run/{samba/,}winbindd.pid rwk,
|
||||
/{var/,}run/samba/winbindd/ rw,
|
||||
/{var/,}run/samba/winbindd/pipe w,
|
||||
/{var/,}run/user/*/krb5cc/* rwk,
|
||||
|
Reference in New Issue
Block a user