| opensuse10.3 |
/usr/sbin/squid |
# $Id: usr.sbin.squid 697 2007-05-25 03:09:30Z steve-beattie $
# ------------------------------------------------------------------
#
# Copyright (C) 2002-2006 Novell/SUSE
#
# This program is free software; you can redistribute it and/or
# modify it under the terms of version 2 of the GNU General Public
# License published by the Free Software Foundation.
#
# ------------------------------------------------------------------
#include <tunables/global>
/usr/sbin/squid {
#include <abstractions/base>
#include <abstractions/consoles>
#include <abstractions/kerberosclient>
#include <abstractions/nameservice>
capability setgid,
capability setuid,
network inet raw,
/dev/tty rw,
/etc/mtab r,
/etc/squid/* r,
/usr/lib/squid/* rmix,
/usr/sbin/digest_pw_auth rmix,
/usr/sbin/diskd rmix,
/usr/sbin/getpwname_auth rmix,
/usr/sbin/ip_user_check rmix,
/usr/sbin/msnt_auth rmix,
/usr/sbin/ncsa_auth rmix,
/usr/sbin/no_check.pl rmix,
/usr/sbin/ntlm_auth rmix,
/usr/sbin/pam_auth rmix,
/usr/sbin/pinger ixr,
/usr/sbin/rcsquid rmix,
/usr/sbin/smb_auth rmix,
/usr/sbin/smb_auth.pl rmix,
/usr/sbin/smb_auth.sh rmix,
/usr/sbin/squid rmix,
/usr/sbin/squid_ldap_auth rmix,
/usr/sbin/squid_ldap_group rmix,
/usr/sbin/squid_ldapauth rmix,
/usr/sbin/squid_unix_group rmix,
/usr/sbin/squidclient rmix,
/usr/sbin/unlinkd rmix,
/usr/sbin/wbinfo_group.pl rmix,
/usr/sbin/yp_auth rmix,
/usr/share/squid/** r,
/var/cache/squid/** lrw,
/var/log/squid/access.log w,
/var/log/squid/cache.log rw,
/var/log/squid/store.log w,
/var/run/nscd/services r,
/var/run/squid.pid lrw,
@{PROC}/[0-9]*/mounts r,
@{PROC}/mounts r,
}
|
8 months ago |
d |
93 |
kaizer |
Edit |
History |
|
| opensuse10.3 |
/usr/sbin/scanlogd |
#include <tunables/global>
/usr/sbin/scanlogd {
#include <abstractions/base>
#include <abstractions/nameservice>
capability net_raw,
capability setgid,
capability setuid,
capability sys_chroot,
network inet raw,
network packet dgram,
network packet raw,
/usr/sbin/scanlogd mr,
}
|
8 months ago |
scanlogd |
98 |
kaizer |
Edit |
History |
|
| opensuse10.3 |
/usr/local/bin/logsurfer |
#include <tunables/global>
/usr/local/bin/logsurfer {
#include <abstractions/base>
#include <abstractions/bash>
#include <abstractions/consoles>
#include <abstractions/nameservice>
#include <abstractions/user-tmp>
/bin/bash ixr,
/bin/cat ixr,
/bin/rm ixr,
/etc/gai.conf r,
/etc/logsurfer.conf r,
/etc/postfix/dynamicmaps.cf r,
/etc/postfix/main.cf r,
/proc/meminfo r,
/proc/net/if_inet6 r,
/proc/sys/kernel/ngroups_max r,
/usr/bin/tr ixr,
/usr/local/bin/logsurfer mr,
/usr/local/bin/start-mail ixr,
/usr/sbin/postdrop ixr,
/usr/sbin/sendmail ixr,
/var/log/logsurfer r,
/var/run/logsurfer/logsurfer.pid w,
/var/spool/postfix/** rw,
}
|
8 months ago |
scanlogd |
82 |
kaizer |
Edit |
History |
|