File: kresd.apparmor

package info (click to toggle)
knot-resolver 5.6.0-1%2Bdeb12u1
  • links: PTS, VCS
  • area: main
  • in suites: bookworm
  • size: 16,088 kB
  • sloc: javascript: 42,732; ansic: 34,753; python: 4,603; cpp: 2,107; sh: 1,883; makefile: 199; xml: 193
file content (29 lines) | stat: -rw-r--r-- 703 bytes parent folder | download | duplicates (5)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
#include <tunables/global>

/usr/sbin/kresd {
  #include <abstractions/base>
  #include <abstractions/p11-kit>
  #include <abstractions/nameservice>
  capability net_bind_service,
  capability setgid,
  capability setuid,
  # seems to be needed during start to read /var/lib/knot-resolver
  # while we still run as root.
  capability dac_override,

  network tcp,
  network udp,

  /proc/sys/net/core/somaxconn r,
  /etc/knot-resolver/* r,
  /var/lib/knot-resolver/ r,
  /var/lib/knot-resolver/** rwlk,

  # modules
  /usr/lib{,64}/kdns_modules/*.lua r,
  /usr/lib{,64}/kdns_modules/*.so rm,

  # Site-specific additions and overrides. See local/README for details.
  #include <local/usr.sbin.kresd>
}