mirror of
https://gitlab.com/apparmor/apparmor
synced 2025-08-30 05:47:59 +00:00
cleanup usr.sbin.nscd profile
From: Kshitij Gupta <kgupta8592@gmail.com> This patch removes rules covered by abstractions in nscd profile: - the network rules are in abstractions/nameservice - @{PROC}/filesystems is in abstractions/base - /{,var/}run/avahi-daemon/socket is in abstractions/nameservice - /tmp/.winbindd/pipe and /var/lib/samba/winbindd_privileged/pipe are in abstractions/winbind via abstractions/nameservice Acked-by: Steve Beattie <steve@nxnw.org>
This commit is contained in:
parent
3093465dc7
commit
a32c85c1c2
@ -21,16 +21,10 @@
|
|||||||
capability setgid,
|
capability setgid,
|
||||||
capability setuid,
|
capability setuid,
|
||||||
|
|
||||||
network inet dgram,
|
|
||||||
network inet stream,
|
|
||||||
|
|
||||||
/etc/netgroup r,
|
/etc/netgroup r,
|
||||||
/etc/nscd.conf r,
|
/etc/nscd.conf r,
|
||||||
/tmp/.winbindd/pipe rw,
|
|
||||||
/usr/sbin/nscd rmix,
|
/usr/sbin/nscd rmix,
|
||||||
/var/lib/samba/winbindd_privileged/pipe rw,
|
|
||||||
/{,var/}run/.nscd_socket wl,
|
/{,var/}run/.nscd_socket wl,
|
||||||
/{,var/}run/avahi-daemon/socket w,
|
|
||||||
/{,var/}run/nscd/ rw,
|
/{,var/}run/nscd/ rw,
|
||||||
/{,var/}run/nscd/db* rwl,
|
/{,var/}run/nscd/db* rwl,
|
||||||
/{,var/}run/nscd/socket wl,
|
/{,var/}run/nscd/socket wl,
|
||||||
@ -41,7 +35,6 @@
|
|||||||
@{PROC}/@{pid}/fd/* r,
|
@{PROC}/@{pid}/fd/* r,
|
||||||
@{PROC}/@{pid}/maps r,
|
@{PROC}/@{pid}/maps r,
|
||||||
@{PROC}/@{pid}/mounts r,
|
@{PROC}/@{pid}/mounts r,
|
||||||
@{PROC}/filesystems r,
|
|
||||||
|
|
||||||
# Site-specific additions and overrides. See local/README for details.
|
# Site-specific additions and overrides. See local/README for details.
|
||||||
#include <local/usr.sbin.nscd>
|
#include <local/usr.sbin.nscd>
|
||||||
|
Loading…
x
Reference in New Issue
Block a user