# ------------------------------------------------------------------ # # Copyright (C) 2002-2009 Novell/SUSE # Copyright (C) 2009-2011 Canonical Ltd. # # This program is free software; you can redistribute it and/or # modify it under the terms of version 2 of the GNU General Public # License published by the Free Software Foundation. # # ------------------------------------------------------------------ # Many programs wish to perform nameservice-like operations, such as # looking up users by name or id, groups by name or id, hosts by name # or IP, etc. These operations may be performed through files, dns, # NIS, NIS+, LDAP, hesiod, wins, etc. Allow them all here. /etc/group r, /etc/host.conf r, /etc/hosts r, /etc/nsswitch.conf r, /etc/gai.conf r, /etc/passwd r, /etc/protocols r, # libtirpc (used for NIS/YP login) needs this /etc/netconfig r, # When using libnss-extrausers, the passwd and group files are merged from # an alternate path /var/lib/extrausers/group r, /var/lib/extrausers/passwd r, # NSS records from systemd-userdbd.service /{,var/}run/systemd/userdb/ r, /{,var/}run/systemd/userdb/io.systemd.{NameServiceSwitch,Multiplexer,DynamicUser,Home} r, @{PROC}/sys/kernel/random/boot_id r, # When using sssd, the passwd and group files are stored in an alternate path # and the nss plugin also needs to talk to a pipe /var/lib/sss/mc/group r, /var/lib/sss/mc/initgroups r, /var/lib/sss/mc/passwd r, /var/lib/sss/pipes/nss rw, /etc/resolv.conf r, # On systems where /etc/resolv.conf is managed programmatically, it is # a symlink to /{,var/}run/(whatever program is managing it)/resolv.conf. /{,var/}run/{resolvconf,NetworkManager,systemd/resolve,connman,netconfig}/resolv.conf r, /etc/resolvconf/run/resolv.conf r, /{,var/}run/systemd/resolve/stub-resolv.conf r, /etc/samba/lmhosts r, /etc/services r, # db backend /var/lib/misc/*.db r, # The Name Service Cache Daemon can cache lookups, sometimes leading # to vast speed increases when working with network-based lookups. /{,var/}run/.nscd_socket rw, /{,var/}run/nscd/socket rw, /{var/db,var/cache,var/lib,var/run,run}/nscd/{passwd,group,services,hosts} r, # nscd renames and unlinks files in it's operation that clients will # have open /{,var/}run/nscd/db* rmix, # The nss libraries are sometimes used in addition to PAM; make sure # they are available /{usr/,}lib{,32,64}/libnss_*.so* mr, /{usr/,}lib/@{multiarch}/libnss_*.so* mr, /etc/default/nss r, # avahi-daemon is used for mdns4 resolution /{,var/}run/avahi-daemon/socket rw, # libnl-3-200 via libnss-gw-name @{PROC}/@{pid}/net/psched r, /etc/libnl-*/classid r, # nis #include <abstractions/nis> # ldap #include <abstractions/ldapclient> # winbind #include <abstractions/winbind> # likewise #include <abstractions/likewise> # mdnsd #include <abstractions/mdns> # kerberos #include <abstractions/kerberosclient> # resolve # # Allow access to the safe members of the systemd-resolved D-Bus API: # # https://www.freedesktop.org/wiki/Software/systemd/resolved/ # # This API may be used directly over the D-Bus system bus or it may be used # indirectly via the nss-resolve plugin: # # https://www.freedesktop.org/software/systemd/man/nss-resolve.html # #include <abstractions/dbus-strict> dbus send bus=system path="/org/freedesktop/resolve1" interface="org.freedesktop.resolve1.Manager" member="Resolve{Address,Hostname,Record,Service}" peer=(name="org.freedesktop.resolve1"), # libnss-systemd # # https://systemd.io/USER_GROUP_API/ # https://systemd.io/USER_RECORD/ # https://www.freedesktop.org/software/systemd/man/nss-systemd.html # # Allow User/Group lookups via common VarLink socket APIs. Applications need # to either consult all of them or the io.systemd.Multiplexer frontend. /run/systemd/userdb/ r, /run/systemd/userdb/io.systemd.Multiplexer rw, /run/systemd/userdb/io.systemd.DynamicUser rw, # systemd-exec users /run/systemd/userdb/io.systemd.Home rw, # systemd-home dirs /run/systemd/userdb/io.systemd.NameServiceSwitch rw, # UNIX/glibc NSS # Also allow lookups for systemd-exec's DynamicUsers via D-Bus # https://www.freedesktop.org/software/systemd/man/systemd.exec.html dbus send bus=system path="/org/freedesktop/systemd1" interface="org.freedesktop.systemd1.Manager" member="{GetDynamicUsers,LookupDynamicUserByName,LookupDynamicUserByUID}" peer=(name="org.freedesktop.systemd1"), # TCP/UDP network access network inet stream, network inet6 stream, network inet dgram, network inet6 dgram, # TODO: adjust when support finer-grained netlink rules # Netlink raw needed for nscd network netlink raw, # interface details @{PROC}/@{pid}/net/route r,
Name | Type | Size | Permission | Actions |
---|---|---|---|---|
apparmor_api | Folder | 0755 |
|
|
ubuntu-browsers.d | Folder | 0755 |
|
|
X | File | 1.72 KB | 0644 |
|
apache2-common | File | 849 B | 0644 |
|
aspell | File | 308 B | 0644 |
|
audio | File | 1.82 KB | 0644 |
|
authentication | File | 1.55 KB | 0644 |
|
base | File | 6.39 KB | 0644 |
|
bash | File | 1.48 KB | 0644 |
|
consoles | File | 798 B | 0644 |
|
cups-client | File | 714 B | 0644 |
|
dbus | File | 593 B | 0644 |
|
dbus-accessibility | File | 630 B | 0644 |
|
dbus-accessibility-strict | File | 637 B | 0644 |
|
dbus-session | File | 638 B | 0644 |
|
dbus-session-strict | File | 919 B | 0644 |
|
dbus-strict | File | 677 B | 0644 |
|
dconf | File | 246 B | 0644 |
|
dovecot-common | File | 562 B | 0644 |
|
dri-common | File | 434 B | 0644 |
|
dri-enumerate | File | 281 B | 0644 |
|
enchant | File | 1.96 KB | 0644 |
|
evince | File | 4.29 KB | 0644 |
|
fcitx | File | 456 B | 0644 |
|
fcitx-strict | File | 712 B | 0644 |
|
fonts | File | 2.04 KB | 0644 |
|
freedesktop.org | File | 1.26 KB | 0644 |
|
gnome | File | 3.54 KB | 0644 |
|
gnupg | File | 356 B | 0644 |
|
ibus | File | 1 KB | 0644 |
|
kde | File | 2.71 KB | 0644 |
|
kde-globals-write | File | 298 B | 0644 |
|
kde-icon-cache-write | File | 138 B | 0644 |
|
kde-language-write | File | 458 B | 0644 |
|
kerberosclient | File | 1.14 KB | 0644 |
|
ldapclient | File | 754 B | 0644 |
|
libpam-systemd | File | 659 B | 0644 |
|
likewise | File | 489 B | 0644 |
|
mdns | File | 457 B | 0644 |
|
mesa | File | 577 B | 0644 |
|
mir | File | 593 B | 0644 |
|
mozc | File | 471 B | 0644 |
|
mysql | File | 641 B | 0644 |
|
nameservice | File | 4.96 KB | 0644 |
|
nis | File | 524 B | 0644 |
|
nvidia | File | 649 B | 0644 |
|
opencl | File | 269 B | 0644 |
|
opencl-common | File | 404 B | 0644 |
|
opencl-intel | File | 564 B | 0644 |
|
opencl-mesa | File | 527 B | 0644 |
|
opencl-nvidia | File | 785 B | 0644 |
|
opencl-pocl | File | 2.75 KB | 0644 |
|
openssl | File | 470 B | 0644 |
|
orbit2 | File | 93 B | 0644 |
|
p11-kit | File | 899 B | 0644 |
|
perl | File | 872 B | 0644 |
|
php | File | 1.02 KB | 0644 |
|
php5 | File | 105 B | 0644 |
|
postfix-common | File | 1.17 KB | 0644 |
|
private-files | File | 1.51 KB | 0644 |
|
private-files-strict | File | 1.02 KB | 0644 |
|
python | File | 1.5 KB | 0644 |
|
qt5 | File | 762 B | 0644 |
|
qt5-compose-cache-write | File | 278 B | 0644 |
|
qt5-settings-write | File | 398 B | 0644 |
|
recent-documents-write | File | 346 B | 0644 |
|
ruby | File | 906 B | 0644 |
|
samba | File | 830 B | 0644 |
|
smbpass | File | 476 B | 0644 |
|
ssl_certs | File | 1.26 KB | 0644 |
|
ssl_keys | File | 790 B | 0644 |
|
svn-repositories | File | 1.61 KB | 0644 |
|
ubuntu-bittorrent-clients | File | 698 B | 0644 |
|
ubuntu-browsers | File | 1.63 KB | 0644 |
|
ubuntu-console-browsers | File | 611 B | 0644 |
|
ubuntu-console-email | File | 601 B | 0644 |
|
ubuntu-email | File | 977 B | 0644 |
|
ubuntu-feed-readers | File | 339 B | 0644 |
|
ubuntu-gnome-terminal | File | 182 B | 0644 |
|
ubuntu-helpers | File | 3.32 KB | 0644 |
|
ubuntu-konsole | File | 343 B | 0644 |
|
ubuntu-media-players | File | 2.18 KB | 0644 |
|
ubuntu-unity7-base | File | 2.39 KB | 0644 |
|
ubuntu-unity7-launcher | File | 191 B | 0644 |
|
ubuntu-unity7-messaging | File | 192 B | 0644 |
|
ubuntu-xterm | File | 237 B | 0644 |
|
user-download | File | 876 B | 0644 |
|
user-mail | File | 837 B | 0644 |
|
user-manpages | File | 889 B | 0644 |
|
user-tmp | File | 654 B | 0644 |
|
user-write | File | 864 B | 0644 |
|
video | File | 127 B | 0644 |
|
vulkan | File | 503 B | 0644 |
|
wayland | File | 580 B | 0644 |
|
web-data | File | 705 B | 0644 |
|
winbind | File | 739 B | 0644 |
|
wutmp | File | 585 B | 0644 |
|
xad | File | 883 B | 0644 |
|
xdg-desktop | File | 673 B | 0644 |
|