mirror of
https://gitlab.com/apparmor/apparmor
synced 2025-08-23 02:27:12 +00:00
Merge profiles: add fixes for samba from issue #386
Signed-off-by: Alex Murray <alex.murray@canonical.com> Fixes: https://gitlab.com/apparmor/apparmor/-/issues/386 MR: https://gitlab.com/apparmor/apparmor/-/merge_requests/1219 Approved-by: John Johansen <john@jjmx.net> Merged-by: John Johansen <john@jjmx.net> (cherry picked from commit 1457eada8b421b4f39eb6e1381efecd2f3adcac7) Signed-off-by: John Johansen <john.johansen@canonical.com>
This commit is contained in:
parent
8d6174e300
commit
dcb3493d19
@ -16,6 +16,8 @@ include <tunables/global>
|
|||||||
profile samba-dcerpcd /usr/lib*/samba/{,samba/}samba-dcerpcd {
|
profile samba-dcerpcd /usr/lib*/samba/{,samba/}samba-dcerpcd {
|
||||||
include <abstractions/samba-rpcd>
|
include <abstractions/samba-rpcd>
|
||||||
|
|
||||||
|
capability sys_resource,
|
||||||
|
|
||||||
@{run}/{,samba/}samba-dcerpcd.pid rwk,
|
@{run}/{,samba/}samba-dcerpcd.pid rwk,
|
||||||
|
|
||||||
/usr/lib*/samba/{,samba/}samba-dcerpcd mr,
|
/usr/lib*/samba/{,samba/}samba-dcerpcd mr,
|
||||||
|
@ -15,8 +15,13 @@ include <tunables/global>
|
|||||||
|
|
||||||
profile samba-rpcd /usr/lib*/samba/{,samba/}rpcd_{mdssvc,epmapper,rpcecho,fsrvp,lsad,winreg} {
|
profile samba-rpcd /usr/lib*/samba/{,samba/}rpcd_{mdssvc,epmapper,rpcecho,fsrvp,lsad,winreg} {
|
||||||
include <abstractions/samba-rpcd>
|
include <abstractions/samba-rpcd>
|
||||||
|
|
||||||
|
capability sys_resource,
|
||||||
|
|
||||||
/usr/lib*/samba/{,samba/}rpcd_{mdssvc,epmapper,rpcecho,fsrvp,lsad,winreg} mr,
|
/usr/lib*/samba/{,samba/}rpcd_{mdssvc,epmapper,rpcecho,fsrvp,lsad,winreg} mr,
|
||||||
|
|
||||||
|
@{run}/samba/ncalrpc/np/lsarpc wr,
|
||||||
|
@{run}/samba/ncalrpc/np/mdssvc wr,
|
||||||
@{run}/samba/ncalrpc/np/winreg wr,
|
@{run}/samba/ncalrpc/np/winreg wr,
|
||||||
|
|
||||||
# Site-specific additions and overrides. See local/README for details.
|
# Site-specific additions and overrides. See local/README for details.
|
||||||
|
@ -17,8 +17,16 @@ profile samba-rpcd-classic /usr/lib*/samba/{,samba/}rpcd_classic {
|
|||||||
include <abstractions/samba-rpcd>
|
include <abstractions/samba-rpcd>
|
||||||
include <abstractions/wutmp>
|
include <abstractions/wutmp>
|
||||||
|
|
||||||
|
capability sys_resource,
|
||||||
|
|
||||||
/usr/lib*/samba/{,samba/}rpcd_classic mr,
|
/usr/lib*/samba/{,samba/}rpcd_classic mr,
|
||||||
|
|
||||||
|
@{run}/samba/ncalrpc/np/srvsvc wr,
|
||||||
|
@{run}/samba/ncalrpc/np/winreg wr,
|
||||||
|
/dev/urandom rw,
|
||||||
|
|
||||||
|
/usr/lib*/samba/{,samba/}samba-dcerpcd Px -> samba-dcerpcd,
|
||||||
|
|
||||||
@{HOMEDIRS}/** lrwk,
|
@{HOMEDIRS}/** lrwk,
|
||||||
|
|
||||||
# Site-specific additions and overrides. See local/README for details.
|
# Site-specific additions and overrides. See local/README for details.
|
||||||
|
@ -8,6 +8,7 @@ profile nmbd /usr/{bin,sbin}/nmbd {
|
|||||||
include <abstractions/samba>
|
include <abstractions/samba>
|
||||||
|
|
||||||
capability net_bind_service,
|
capability net_bind_service,
|
||||||
|
capability sys_resource,
|
||||||
|
|
||||||
@{PROC}/sys/kernel/core_pattern r,
|
@{PROC}/sys/kernel/core_pattern r,
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user