On Mon, Dec 12, 2016 at 09:50:51PM +0100, daniel curtis wrote:
> /sbin/initctl Ux,
> /sbin/runlevel Ux,
> capability fsetid,
> /etc/lsb-base-logging.sh r,

Hi Daniel, yes, all these should be fine.

('capability fsetid' is perhaps the more unfortunate one; I'm not sure why
it would be needed. At least the file writes are confined by the rest of
the profile, so a compromised logrotate process wouldn't necessarily have
much chance to abuse it.)

Thanks

Attachment: signature.asc
Description: PGP signature

-- 
AppArmor mailing list
[email protected]
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/apparmor

Reply via email to