]> git.lizzy.rs Git - torbrowser-launcher.git/commitdiff
AppArmor: silence sys_admin capability
authorJonas Witschel <diabonas@archlinux.org>
Sun, 12 Jul 2020 18:10:39 +0000 (20:10 +0200)
committerJonas Witschel <diabonas@archlinux.org>
Tue, 18 Aug 2020 10:41:52 +0000 (12:41 +0200)
This permission is unsuccessfully requested during every start of Tor
Browser 9.5.3, silence it for cleaner logs.

apparmor/torbrowser.Browser.firefox

index ece31599564c6c73b5d9187424a689844cf72eab..4363cdfac0a2d021ff7c3f395022b5b30cf4509d 100644 (file)
@@ -124,6 +124,7 @@ profile torbrowser_firefox @{torbrowser_firefox_executable} {
   deny /sys/devices/system/cpu/*/cache/index[0-9]*/size r,
   deny /run/user/[0-9]*/dconf/user rw,
   deny /usr/bin/lsb_release x,
+  deny capability sys_admin,
 
   # Silence denial logs about PulseAudio
   deny /etc/pulse/client.conf r,