forked from I2P_Developers/i2p.i2p
updates to apparmor profiles
- hardening (restrict access to proc to owner) - removing files covered by abstractions - indentation per apparmor profile style
This commit is contained in:
8
debian/apparmor/usr.bin.i2prouter
vendored
8
debian/apparmor/usr.bin.i2prouter
vendored
@@ -1,4 +1,4 @@
|
||||
# Last Modified: Thu Jan 29 03:17:01 2015
|
||||
# Last Modified: Sun Apr 12 22:08:32 2015
|
||||
# vim:syntax=apparmor et ts=8 sw=4
|
||||
|
||||
#include <tunables/global>
|
||||
@@ -9,8 +9,10 @@
|
||||
|
||||
/usr/bin/i2prouter r,
|
||||
|
||||
@{PROC}/[0-9]*/stat r,
|
||||
@{PROC}/[0-9]*/cmdline r,
|
||||
@{PROC}/1/comm r,
|
||||
owner @{PROC}/[0-9]*/ r,
|
||||
owner @{PROC}/[0-9]*/stat r,
|
||||
owner @{PROC}/[0-9]*/cmdline r,
|
||||
@{PROC}/uptime r,
|
||||
@{PROC}/sys/kernel/pid_max r,
|
||||
|
||||
|
Reference in New Issue
Block a user