~ubuntu-branches/ubuntu/raring/apparmor/raring

« back to all changes in this revision

Viewing changes to profiles/extras/usr.sbin.useradd

  • Committer: Bazaar Package Importer
  • Author(s): Kees Cook
  • Date: 2007-03-23 16:42:01 UTC
  • Revision ID: james.westby@ubuntu.com-20070323164201-jkax6f0oku087b7l
Tags: upstream-2.0.1+510.dfsg
ImportĀ upstreamĀ versionĀ 2.0.1+510.dfsg

Show diffs side-by-side

added added

removed removed

Lines of Context:
 
1
# $Id: usr.sbin.useradd 228 2006-11-13 09:53:10Z seth_arnold $
 
2
# vim:syntax=apparmor
 
3
# ------------------------------------------------------------------
 
4
#
 
5
#    Copyright (C) 2002-2005 Novell/SUSE
 
6
#
 
7
#    This program is free software; you can redistribute it and/or
 
8
#    modify it under the terms of version 2 of the GNU General Public
 
9
#    License published by the Free Software Foundation.
 
10
#
 
11
# ------------------------------------------------------------------
 
12
 
 
13
#include <tunables/global>
 
14
 
 
15
/usr/sbin/useradd {
 
16
  #include <abstractions/authentication>
 
17
  #include <abstractions/base>
 
18
  #include <abstractions/bash>
 
19
  #include <abstractions/perl>
 
20
  #include <abstractions/consoles>
 
21
  #include <abstractions/nameservice>
 
22
 
 
23
  capability chown,
 
24
  capability dac_override,
 
25
  capability fowner,
 
26
  capability fsetid,
 
27
  capability sys_resource,
 
28
 
 
29
  /bin/bash mixr,
 
30
  /etc/.pwd.lock rw,
 
31
  /etc/default/useradd r,
 
32
  /etc/group* rwl,
 
33
  /etc/gshadow* rwl,
 
34
  /etc/login.defs r,
 
35
  /etc/passwd* rwl,
 
36
  /etc/shadow* rwl,
 
37
  /etc/pwdutils/logging r,
 
38
  /etc/skel r,
 
39
  /etc/skel/** r,
 
40
  @{HOMEDIRS}**  rw,
 
41
  /proc/*/mounts r,
 
42
  /proc/filesystems r,
 
43
  /usr/lib*/pwdutils/*so* mr,
 
44
  /usr/sbin/adduser rmix,
 
45
  /usr/sbin/useradd rmix,
 
46
  /usr/sbin/useradd.local rmix,
 
47
  /var/log/faillog rw,
 
48
  /var/log/lastlog rw,
 
49
  /var/run/nscd.pid rw,
 
50
  /var/run/utmp rw,
 
51
  /var/spool/mail/* rw,
 
52
}