[apparmor] Deny mount globally

2019-08-29 Thread Kobus Goosen
Hi, I just wanted to ask if there is an elegant way to block mounting/unmounting in general. I have an industrial device that has a read-only rootfs, so there's limited system damage that a user could make. However I'd like to disable mounting so it's never possible to remount the rootfs in read/wr

Re: [apparmor] Apparmor

2019-08-29 Thread Seth Arnold
On Thu, Aug 29, 2019 at 04:02:52PM +0300, Олександр Нещадим wrote: > I want to limit the users of my computer so that they cannot transfer their > files to other users. I limited the chmod command. > But through the Nautilus program, users can change the properties of files. > > Tell me how to lim

[apparmor] Apparmor

2019-08-29 Thread Олександр Нещадим
I want to limit the users of my computer so that they cannot transfer their files to other users. I limited the chmod command. But through the Nautilus program, users can change the properties of files. Tell me how to limit users who own files. I wanted to do this through the Apparmore profile fo