aboutsummaryrefslogtreecommitdiff
path: root/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-dns
diff options
context:
space:
mode:
Diffstat (limited to 'contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-dns')
-rw-r--r--contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-dns43
1 files changed, 43 insertions, 0 deletions
diff --git a/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-dns b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-dns
new file mode 100644
index 000000000..960cf09b5
--- /dev/null
+++ b/contrib/apparmor/usr.local.lib.gnunet.libexec.gnunet-helper-dns
@@ -0,0 +1,43 @@
1# Last Modified: Mon Jul 27 15:24:34 2015
2#include <tunables/global>
3
4/usr/local/lib/gnunet/libexec/gnunet-helper-dns flags=(complain) {
5 #include <abstractions/gnunet-common>
6
7 capability net_admin,
8 capability net_raw,
9 capability setuid,
10
11 /dev/net/tun rw,
12 /dev/null rw,
13
14 /etc/gai.conf r,
15 /etc/group r,
16 /etc/iproute2/rt_tables r,
17 /etc/nsswitch.conf r,
18 /etc/protocols r,
19
20 @{PROC}/@{pid}/net/ip_tables_names r,
21 @{PROC}/sys/net/ipv4/conf/all/rp_filter rw,
22 @{PROC}/sys/net/ipv4/conf/default/rp_filter rw,
23
24 /usr/bin/ip rix,
25 /usr/bin/sysctl rix,
26 /usr/bin/xtables-multi rix,
27
28 /usr/lib/iptables/libxt_MARK.so mr,
29 /usr/lib/iptables/libxt_owner.so mr,
30 /usr/lib/iptables/libxt_standard.so mr,
31 /usr/lib/iptables/libxt_udp.so mr,
32
33 /usr/lib/ld-*.so r,
34 /usr/lib/libip4tc.so.* mr,
35 /usr/lib/libip6tc.so.* mr,
36 /usr/lib/libnss_files-*.so mr,
37
38 /usr/lib/libxtables.so.* mr,
39
40 /usr/lib/locale/locale-archive r,
41
42 /usr/local/lib/gnunet/libexec/gnunet-helper-dns mr,
43}