Merge lp:~elmo/apparmor-profiles/lldpd into lp:apparmor-profiles
Proposed by
James Troup
Status: | Merged |
---|---|
Merged at revision: | 140 |
Proposed branch: | lp:~elmo/apparmor-profiles/lldpd |
Merge into: | lp:apparmor-profiles |
Diff against target: |
169 lines (+150/-0) 4 files modified
ubuntu/10.04/usr.sbin.lldpd (+33/-0) ubuntu/12.04/usr.sbin.lldpd (+39/-0) ubuntu/13.10/usr.sbin.lldpd (+39/-0) ubuntu/14.04/usr.sbin.lldpd (+39/-0) |
To merge this branch: | bzr merge lp:~elmo/apparmor-profiles/lldpd |
Related bugs: |
Reviewer | Review Type | Date Requested | Status |
---|---|---|---|
AppArmor Developers | Pending | ||
Review via email: mp+202092@code.launchpad.net |
Description of the change
Profile for lldpd. We're using this on 10.04 and 12.04 (in production) and 13.10. I've blind copied it to 14.04 as that seems to be standard practice.
To post a comment you must log in.
Hello,
Am Freitag, 17. Januar 2014 schrieb James Troup:
> James Troup has proposed merging lp:~elmo/apparmor-profiles/lldpd into
> lp:apparmor-profiles.
> For more details, see: /code.launchpad .net/~elmo/ apparmor- profiles/ lldpd/+ merge/202092
> https:/
> === added file 'ubuntu/ 10.04/usr. sbin.lldpd' 10.04/usr. sbin.lldpd 1970-01-01 00:00:00 +0000 10.04/usr. sbin.lldpd 2014-01-17 13:13:03 +0000 nameservice> lldpd.socket w, lsb_release rUx,
> --- ubuntu/
> +++ ubuntu/
> @@ -0,0 +1,33 @@
> +# Author: James Troup <email address hidden>
> +
> +#include <tunables/global>
> +
> +/usr/sbin/lldpd {
> + #include <abstractions/base>
> + #include <abstractions/
> +
> + capability chown,
> + capability dac_override,
> + capability fowner,
> + capability fsetid,
> + capability kill,
> + capability net_admin,
> + capability net_raw,
> + capability setgid,
> + capability setuid,
> + capability sys_chroot,
> + capability sys_module,
> +
> + network packet raw,
> +
> + /usr/sbin/lldpcli rix,
> + /usr/sbin/lldpd mr,
> +
> + /var/run/lldpd.pid rw,
> + /var/run/
> + /usr/bin/
Given the impressive set of capabilities, I'd prefer to avoid Ux. What
about creating a profile (or child profile) for lsb_release?
(seems to be different in the profiles for newer releases - I'm not sure
if it's still worth fixing for 10.04)
Regards,
Christian Boltz powersave/ cpufreq contains the line: /bugzilla. novell. com/show_ bug.cgi? id=183704]
--
> /etc/sysconfig/
> # the next lover CPU frequency. Increasing this value lowers the
^^^^^
we should keep that one ;)
[Michael Gross in https:/