kresd.apparmor 672 Bytes
Newer Older
1 2
#include <tunables/global>

3
/usr/sbin/kresd {
4
  #include <abstractions/base>
5
  #include <abstractions/p11-kit>
6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25
  #include <abstractions/nameservice>
  capability net_bind_service,
  capability setgid,
  capability setuid,
  # seems to be needed during start to read /var/lib/kresd
  # while we still run as root.
  capability dac_override,

  network tcp,
  network udp,

  /proc/sys/net/core/somaxconn r,
  /etc/kresd/* r, 
  /var/lib/kresd/ r,
  /var/lib/kresd/** rwlk,

  # modules
  /usr/lib{,64}/kdns_modules/*.lua r,
  /usr/lib{,64}/kdns_modules/*.so rm,

Marek Vavruša's avatar
Marek Vavruša committed
26
  # Site-specific additions and overrides. See local/README for details.
27
  #include <local/usr.sbin.kresd>
28 29
}