mirror of
https://gitlab.com/apparmor/apparmor
synced 2025-08-31 22:35:35 +00:00
Merge with other profile
This commit is contained in:
@@ -15,21 +15,26 @@ include <tunables/global>
|
|||||||
|
|
||||||
profile lsblk /usr/bin/lsblk {
|
profile lsblk /usr/bin/lsblk {
|
||||||
include <abstractions/base>
|
include <abstractions/base>
|
||||||
|
include <abstractions/consoles>
|
||||||
|
include <abstractions/nameservice-strict>
|
||||||
|
|
||||||
|
capability dac_read_search,
|
||||||
|
|
||||||
@{sys}/block/ r,
|
@{sys}/block/ r,
|
||||||
|
@{sys}/class/block/ r,
|
||||||
@{sys}/dev/block/ r,
|
@{sys}/dev/block/ r,
|
||||||
|
|
||||||
@{sys}/devices/pci[0-9]*:[0-9]*/** r,
|
@{sys}/devices/pci[0-9]*:[0-9]*/** r,
|
||||||
@{sys}/devices/virtual/** r,
|
@{sys}/devices/virtual/** r,
|
||||||
|
@{sys}/devices/platform/** r,
|
||||||
|
|
||||||
|
/dev/sr[0-9]* rk,
|
||||||
|
|
||||||
@{run}/mount/** r,
|
|
||||||
@{run}/udev/data/** r,
|
@{run}/udev/data/** r,
|
||||||
|
|
||||||
|
@{run}/mount/** r,
|
||||||
@{PROC}/swaps r,
|
@{PROC}/swaps r,
|
||||||
@{PROC}/*/mountinfo r,
|
owner @{PROC}/@{pid}/mountinfo r,
|
||||||
|
|
||||||
/etc/nsswitch.conf r,
|
|
||||||
/etc/passwd r,
|
|
||||||
/etc/group r,
|
|
||||||
|
|
||||||
include if exists <local/lsblk>
|
include if exists <local/lsblk>
|
||||||
}
|
}
|
||||||
|
Reference in New Issue
Block a user