mirror of
https://github.com/Kicksecure/security-misc.git
synced 2025-01-12 14:39:31 -05:00
Create usr.lib.security-misc.permission-lockdown
This commit is contained in:
parent
d832ab91bd
commit
29b05546e4
35
etc/apparmor.d/usr.lib.security-misc.permission-lockdown
Normal file
35
etc/apparmor.d/usr.lib.security-misc.permission-lockdown
Normal file
@ -0,0 +1,35 @@
|
||||
#include <tunables/global>
|
||||
|
||||
/usr/lib/security-misc/permission-lockdown flags=(attach_disconnected) {
|
||||
#include <abstractions/bash>
|
||||
|
||||
capability dac_override,
|
||||
capability dac_read_search,
|
||||
capability fowner,
|
||||
capability fsetid,
|
||||
|
||||
/bin/bash ix,
|
||||
/bin/chmod mrix,
|
||||
/bin/echo mrix,
|
||||
/bin/mkdir mrix,
|
||||
/bin/touch mrix,
|
||||
/usr/bin/basename mrix,
|
||||
/usr/bin/touch mrix,
|
||||
/usr/lib/security-misc/permission-lockdown r,
|
||||
|
||||
/home/*/ w,
|
||||
|
||||
/{usr/,}lib{,32,64}/** mr,
|
||||
|
||||
/etc/ld.so.cache r,
|
||||
owner /etc/locale.alias r,
|
||||
owner /etc/nsswitch.conf r,
|
||||
owner /etc/passwd r,
|
||||
|
||||
owner /var/cache/security-misc/state-files/ rw,
|
||||
owner /var/cache/security-misc/state-files/* rw,
|
||||
|
||||
/dev/tty rw,
|
||||
|
||||
#include <local/usr.lib.security-misc.permission-lockdown>
|
||||
}
|
Loading…
Reference in New Issue
Block a user