123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869 |
- profile systemctl-mqtt flags=(attach_disconnected) {
- network inet,
- /systemctl-mqtt/ r,
- /systemctl-mqtt/** r,
- /systemctl-mqtt/.venv/bin/systemctl-mqtt rix,
- /etc/** r,
- /usr/lib/** rm,
- /var/** r,
- deny /bin/** rwklx,
- deny @{PROC}/** rwklx,
- deny /sys/** rwklx,
- dbus (send, receive)
- bus=system
- path=/org/freedesktop/login1
- interface=org.freedesktop.DBus.Introspectable
- member=Introspect
- peer=(label=unconfined),
- dbus (send)
- bus=system
- path=/org/freedesktop/login1
- interface=org.freedesktop.login1.Manager
- member={Inhibit,ListInhibitors,ScheduleShutdown,LockSessions,Suspend}
- peer=(label=unconfined),
- dbus (receive)
- bus=system
- path=/org/freedesktop/login1
- interface=org.freedesktop.login1.Manager
- member=PrepareForShutdown
- peer=(label=unconfined),
- dbus (send)
- bus=system
- path=/org/freedesktop/login1
- interface=org.freedesktop.DBus.Properties
- member=Get
- peer=(label=unconfined),
- dbus (send)
- bus=system
- path=/org/freedesktop/systemd1
- interface=org.freedesktop.systemd1.Manager
- member=RestartUnit
- peer=(label=unconfined),
- }
|