updated apparmor state
This commit is contained in:
parent
c0add92d8d
commit
dff51f8bb3
@ -4,8 +4,8 @@
|
||||
{%- for cfg in apparmor.configs %}
|
||||
apparmor-{{ cfg }}:
|
||||
file.managed:
|
||||
- name: "/etc/apparmor.d/{{ cfg }}"
|
||||
- source: "salt://apparmor/{{ cfg }}.j2"
|
||||
- name: /etc/apparmor.d/{{ cfg }}
|
||||
- source: salt://apparmor/templates/{{ cfg }}.j2
|
||||
- user: root
|
||||
- group: root
|
||||
- mode: "0644"
|
||||
@ -18,4 +18,4 @@ apparmor-reload:
|
||||
service.running:
|
||||
- name: apparmor
|
||||
- enable: true
|
||||
{%- endif %}
|
||||
{%- endif %}
|
||||
|
@ -24,4 +24,4 @@
|
||||
owner @{HOME}/Documents/** rw,
|
||||
|
||||
deny network inet,
|
||||
}
|
||||
}
|
@ -38,4 +38,4 @@
|
||||
deny network inet,
|
||||
deny network inet6,
|
||||
deny network raw,
|
||||
}
|
||||
}
|
@ -74,4 +74,4 @@
|
||||
deny /var/cache/fontconfig/ w,
|
||||
deny owner @{HOME}/.fontconfig/ w,
|
||||
deny owner @{HOME}/.fontconfig/*.cache-*.TMP* w,
|
||||
}
|
||||
}
|
@ -21,4 +21,4 @@
|
||||
owner @{HOME}/.config/spotify/ w,
|
||||
|
||||
owner @{HOME}/Music/** r,
|
||||
}
|
||||
}
|
Loading…
Reference in New Issue
Block a user