updated apparmor state
This commit is contained in:
parent
c0add92d8d
commit
dff51f8bb3
@ -4,8 +4,8 @@
|
|||||||
{%- for cfg in apparmor.configs %}
|
{%- for cfg in apparmor.configs %}
|
||||||
apparmor-{{ cfg }}:
|
apparmor-{{ cfg }}:
|
||||||
file.managed:
|
file.managed:
|
||||||
- name: "/etc/apparmor.d/{{ cfg }}"
|
- name: /etc/apparmor.d/{{ cfg }}
|
||||||
- source: "salt://apparmor/{{ cfg }}.j2"
|
- source: salt://apparmor/templates/{{ cfg }}.j2
|
||||||
- user: root
|
- user: root
|
||||||
- group: root
|
- group: root
|
||||||
- mode: "0644"
|
- mode: "0644"
|
||||||
@ -18,4 +18,4 @@ apparmor-reload:
|
|||||||
service.running:
|
service.running:
|
||||||
- name: apparmor
|
- name: apparmor
|
||||||
- enable: true
|
- enable: true
|
||||||
{%- endif %}
|
{%- endif %}
|
||||||
|
@ -24,4 +24,4 @@
|
|||||||
owner @{HOME}/Documents/** rw,
|
owner @{HOME}/Documents/** rw,
|
||||||
|
|
||||||
deny network inet,
|
deny network inet,
|
||||||
}
|
}
|
@ -38,4 +38,4 @@
|
|||||||
deny network inet,
|
deny network inet,
|
||||||
deny network inet6,
|
deny network inet6,
|
||||||
deny network raw,
|
deny network raw,
|
||||||
}
|
}
|
@ -74,4 +74,4 @@
|
|||||||
deny /var/cache/fontconfig/ w,
|
deny /var/cache/fontconfig/ w,
|
||||||
deny owner @{HOME}/.fontconfig/ w,
|
deny owner @{HOME}/.fontconfig/ w,
|
||||||
deny owner @{HOME}/.fontconfig/*.cache-*.TMP* w,
|
deny owner @{HOME}/.fontconfig/*.cache-*.TMP* w,
|
||||||
}
|
}
|
@ -21,4 +21,4 @@
|
|||||||
owner @{HOME}/.config/spotify/ w,
|
owner @{HOME}/.config/spotify/ w,
|
||||||
|
|
||||||
owner @{HOME}/Music/** r,
|
owner @{HOME}/Music/** r,
|
||||||
}
|
}
|
Loading…
Reference in New Issue
Block a user