From 29b05546e4248bdf95b62ea356bd98767e3a59b0 Mon Sep 17 00:00:00 2001 From: madaidan <50278627+madaidan@users.noreply.github.com> Date: Mon, 28 Oct 2019 14:20:08 +0000 Subject: [PATCH] Create usr.lib.security-misc.permission-lockdown --- .../usr.lib.security-misc.permission-lockdown | 35 +++++++++++++++++++ 1 file changed, 35 insertions(+) create mode 100644 etc/apparmor.d/usr.lib.security-misc.permission-lockdown diff --git a/etc/apparmor.d/usr.lib.security-misc.permission-lockdown b/etc/apparmor.d/usr.lib.security-misc.permission-lockdown new file mode 100644 index 0000000..018090e --- /dev/null +++ b/etc/apparmor.d/usr.lib.security-misc.permission-lockdown @@ -0,0 +1,35 @@ +#include + +/usr/lib/security-misc/permission-lockdown flags=(attach_disconnected) { + #include + + capability dac_override, + capability dac_read_search, + capability fowner, + capability fsetid, + + /bin/bash ix, + /bin/chmod mrix, + /bin/echo mrix, + /bin/mkdir mrix, + /bin/touch mrix, + /usr/bin/basename mrix, + /usr/bin/touch mrix, + /usr/lib/security-misc/permission-lockdown r, + + /home/*/ w, + + /{usr/,}lib{,32,64}/** mr, + + /etc/ld.so.cache r, + owner /etc/locale.alias r, + owner /etc/nsswitch.conf r, + owner /etc/passwd r, + + owner /var/cache/security-misc/state-files/ rw, + owner /var/cache/security-misc/state-files/* rw, + + /dev/tty rw, + + #include +}