/etc/dbus-1/system.d
<?xml version="1.0" encoding="UTF-8"?> <!-- -*- XML -*- --> <!DOCTYPE busconfig PUBLIC "-//freedesktop//DTD D-BUS Bus Configuration 1.0//EN" "http://www.freedesktop.org/standards/dbus/1.0/busconfig.dtd"> <busconfig> <policy user="root"> <allow send_destination="org.freedesktop.systemd1" send_interface="org.freedesktop.systemd1.Manager" send_member="GetUnitProcesses"/> <allow send_destination="org.freedesktop.systemd1" send_interface="org.freedesktop.systemd1.Service" send_member="GetProcesses"/> <allow send_destination="org.freedesktop.systemd1" send_interface="org.freedesktop.systemd1.Slice" send_member="GetProcesses"/> <allow send_destination="org.freedesktop.systemd1" send_interface="org.freedesktop.systemd1.Scope" send_member="GetProcesses"/> <allow send_destination="org.freedesktop.systemd1" send_interface="org.freedesktop.systemd1.Socket" send_member="GetProcesses"/> <allow send_destination="org.freedesktop.systemd1" send_interface="org.freedesktop.systemd1.Mount" send_member="GetProcesses"/> <allow send_destination="org.freedesktop.systemd1" send_interface="org.freedesktop.systemd1.Swap" send_member="GetProcesses"/> </policy> <policy context="default"> <deny send_destination="org.freedesktop.systemd1" send_interface="org.freedesktop.systemd1.Manager" send_member="GetUnitProcesses"/> <deny send_destination="org.freedesktop.systemd1" send_interface="org.freedesktop.systemd1.Service" send_member="GetProcesses"/> <deny send_destination="org.freedesktop.systemd1" send_interface="org.freedesktop.systemd1.Slice" send_member="GetProcesses"/> <deny send_destination="org.freedesktop.systemd1" send_interface="org.freedesktop.systemd1.Scope" send_member="GetProcesses"/> <deny send_destination="org.freedesktop.systemd1" send_interface="org.freedesktop.systemd1.Socket" send_member="GetProcesses"/> <deny send_destination="org.freedesktop.systemd1" send_interface="org.freedesktop.systemd1.Mount" send_member="GetProcesses"/> <deny send_destination="org.freedesktop.systemd1" send_interface="org.freedesktop.systemd1.Swap" send_member="GetProcesses"/> </policy> </busconfig>
.
Edit
..
Edit
cagefs-dbus-hardening.conf
Edit
org.freedesktop.Flatpak.SystemHelper.conf
Edit
org.freedesktop.GeoClue2.Agent.conf
Edit
org.freedesktop.GeoClue2.conf
Edit
org.freedesktop.PolicyKit1.conf
Edit
org.freedesktop.RealtimeKit1.conf
Edit
org.selinux.conf
Edit
teamd.conf
Edit