This commit is contained in:
Patrick Schleizer 2025-01-20 04:29:42 -05:00
parent 51c7010e8f
commit 1b4d1edfc3
No known key found for this signature in database
GPG Key ID: CB8D50BB77BB3C48
5 changed files with 7 additions and 3 deletions

View File

@ -5,12 +5,10 @@
## "/usr/local/etc/permission-hardener.d/20_user.conf" for your custom
## configuration. When security-misc is updated, this file may be overwritten.
## user-sysmaint-split hardens this further.
/usr/bin/pkexec exactwhitelist
/usr/bin/pkexec.security-misc-orig exactwhitelist
## TODO: research
## TODO: Should be handled in user-sysmaint-split?
##
## Required for PolicyKit (Polkit) to function.
##
## https://polkit-devel.freedesktop.narkive.com/zXO4yEg7/documentation-on-polkit-agent-helper-1-and-suid#
@ -24,4 +22,6 @@
## matches both:
## - /usr/lib/policykit-1/polkit-agent-helper-1
## - /lib/policykit-1/polkit-agent-helper-1
##
## user-sysmaint-split hardens this further.
polkit-agent-helper-1 matchwhitelist

View File

@ -5,5 +5,6 @@
## "/usr/local/etc/permission-hardener.d/20_user.conf" for your custom
## configuration. When security-misc is updated, this file may be overwritten.
## TODO: research and document
postqueue matchwhitelist
postdrop matchwhitelist

View File

@ -5,4 +5,5 @@
## "/usr/local/etc/permission-hardener.d/20_user.conf" for your custom
## configuration. When security-misc is updated, this file may be overwritten.
## TODO: research and document
/utempter/utempter matchwhitelist

View File

@ -5,4 +5,5 @@
## "/usr/local/etc/permission-hardener.d/20_user.conf" for your custom
## configuration. When security-misc is updated, this file may be overwritten.
## TODO: research and document
spice-client-glib-usb-acl-helper matchwhitelist

View File

@ -5,4 +5,5 @@
## "/usr/local/etc/permission-hardener.d/20_user.conf" for your custom
## configuration. When security-misc is updated, this file may be overwritten.
## user-sysmaint-split hardens this further.
/usr/bin/sudo exactwhitelist