[apparmor] [patch] cleanup nscd profile

Christian Boltz apparmor at cboltz.de
Mon Dec 1 21:00:14 UTC 2014


Hello,

  @{PROC}/@{pid}/maps r,
is part of abstractions/base - so there's no need to include it in the 
nscd profile.

=== modified file 'profiles/apparmor.d/usr.sbin.nscd'
--- profiles/apparmor.d/usr.sbin.nscd   2014-11-17 19:18:29 +0000
+++ profiles/apparmor.d/usr.sbin.nscd   2014-12-01 20:58:52 +0000
@@ -33,7 +33,6 @@
   /var/log/nscd.log rw,
   @{PROC}/@{pid}/fd/ r,
   @{PROC}/@{pid}/fd/* r,
-  @{PROC}/@{pid}/maps r,
   @{PROC}/@{pid}/mounts r,
 
   # Site-specific additions and overrides. See local/README for details.




Regards,

Christian Boltz
-- 
>ist mein sendmail was da rumpfuscht
Tsss.
Du hast also sendmail laufen _UND VERWENDEST TROTZDEM KEIN MUTT?!!_
                 [Herbert Steinboeck und David Haller in suse-talk]




More information about the AppArmor mailing list