1
# ------------------------------------------------------------------
3
# Copyright (C) 2002-2005 Novell/SUSE
5
# This program is free software; you can redistribute it and/or
6
# modify it under the terms of version 2 of the GNU General Public
7
# License published by the Free Software Foundation.
9
# ------------------------------------------------------------------
13
# (Note that the ldd profile has inlined this file; if you make
14
# modifications here, please consider including them in the ldd
17
# The __canary_death_handler function writes a time-stamped log
18
# message to /dev/log for logging by syslogd. So, /dev/log, timezones,
19
# and localisations of date should be available EVERYWHERE, so
20
# StackGuard, FormatGuard, etc., alerts can be properly logged.
25
/usr/share/locale/** r,
26
/usr/share/zoneinfo/** r,
28
/usr/lib64/locale/** r,
29
/usr/lib64/gconv/*.so r,
30
/usr/lib64/gconv/gconv-modules* r,
32
/usr/lib/gconv/*.so r,
33
/usr/lib/gconv/gconv-modules* r,
35
# used by glibc when binding to ephemeral ports
36
/etc/bindresvport.blacklist r,
38
# ld.so.cache and ld are used to load shared libraries; they are best
39
# available everywhere
41
# 'px' requires a profile to be available for the transition to
42
# function; without a loaded profile, the kernel will fail the exec.
45
/opt/*-linux-uclibc/lib/ld-uClibc*so* px,
47
# we might as well allow everything to use common libraries
50
/lib/power4/lib*.so* r,
51
/lib/power5/lib*.so* r,
52
/lib/power5+/lib*.so* r,
53
/lib64/power4/lib*.so* r,
54
/lib64/power5/lib*.so* r,
55
/lib64/power5+/lib*.so* r,
57
/usr/lib/tls/lib*.so* r,
58
/usr/lib/power4/lib*.so* r,
59
/usr/lib/power5/lib*.so* r,
60
/usr/lib/power5+/lib*.so* r,
62
/lib64/tls/lib*.so* r,
64
/usr/lib64/tls/lib*.so* r,
66
# /dev/null is pretty harmless and frequently used
71
# Sometimes used to determine kernel/user interfaces to use
72
/proc/sys/kernel/version r,
73
# Depending on which glibc routine uses this file, base may not be the
74
# best place -- but many profiles require it, and it is quite harmless.
75
/proc/sys/kernel/ngroups_max r,
77
# glibc's sysconf(3) routine to determine free memory, etc