gnunet-helper-dns 1.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748
  1. # Last Modified: Mon Jul 27 15:24:34 2015
  2. #include <tunables/global>
  3. #include <tunables/gnunet>
  4. profile @{GNUNET_PREFIX}/lib/gnunet/libexec/gnunet-helper-dns {
  5. #include <abstractions/gnunet-suid>
  6. #Capability
  7. capability net_admin,
  8. capability net_raw,
  9. capability setuid,
  10. /dev/net/tun rw,
  11. /dev/null rw,
  12. /etc/gai.conf r,
  13. /etc/group r,
  14. /etc/iproute2/rt_tables r,
  15. /etc/nsswitch.conf r,
  16. /etc/protocols r,
  17. @{PROC}/@{pid}/net/ip_tables_names r,
  18. @{PROC}/sys/net/ipv4/conf/all/rp_filter rw,
  19. @{PROC}/sys/net/ipv4/conf/default/rp_filter rw,
  20. /usr/bin/ip rix,
  21. /usr/bin/sysctl rix,
  22. /usr/bin/xtables-multi rix,
  23. #Librairies
  24. /usr/lib/iptables/libxt_MARK.so mr,
  25. /usr/lib/iptables/libxt_owner.so mr,
  26. /usr/lib/iptables/libxt_standard.so mr,
  27. /usr/lib/iptables/libxt_udp.so mr,
  28. /usr/lib/ld-*.so r,
  29. /usr/lib/libip4tc.so.* mr,
  30. /usr/lib/libip6tc.so.* mr,
  31. /usr/lib/libnss_files-*.so mr,
  32. /usr/lib/libxtables.so.* mr,
  33. /usr/lib/locale/locale-archive r,
  34. @{GNUNET_PREFIX}/lib/gnunet/libexec/gnunet-helper-dns mr,
  35. # Site-specific additions and overrides. See local/README for details.
  36. #include <local/gnunet>
  37. }