Teach AppArmor, that /usr/lib64 may exist.

The apparmor profiles forgot about /usr/lib64 folders, just add lib64
as a possible alternative to lib in the paths
This commit is contained in:
Cedric Bosdonnat 2014-12-15 15:14:48 +01:00 committed by Cédric Bosdonnat
parent 703ef9667a
commit 30c6aecc44
3 changed files with 5 additions and 5 deletions

View File

@ -111,7 +111,7 @@
/usr/bin/qemu-sparc32plus rmix,
/usr/bin/qemu-sparc64 rmix,
/usr/bin/qemu-x86_64 rmix,
/usr/lib/qemu/block-curl.so mr,
/usr/{lib,lib64}/qemu/block-curl.so mr,
# for save and resume
/bin/dash rmix,

View File

@ -1,7 +1,7 @@
# Last Modified: Mon Apr 5 15:10:27 2010
#include <tunables/global>
/usr/lib/libvirt/virt-aa-helper {
profile virt-aa-helper /usr/{lib,lib64}/libvirt/virt-aa-helper {
#include <abstractions/base>
# needed for searching directories
@ -20,7 +20,7 @@
/sys/devices/ r,
/sys/devices/** r,
/usr/lib/libvirt/virt-aa-helper mr,
/usr/{lib,lib64}/libvirt/virt-aa-helper mr,
/sbin/apparmor_parser Ux,
/etc/apparmor.d/libvirt/* r,

View File

@ -44,7 +44,7 @@
/usr/bin/* PUx,
/usr/sbin/* PUx,
/lib/udev/scsi_id PUx,
/usr/lib/xen-common/bin/xen-toolstack PUx,
/usr/{lib,lib64}/xen-common/bin/xen-toolstack PUx,
# force the use of virt-aa-helper
audit deny /sbin/apparmor_parser rwxl,
@ -53,7 +53,7 @@
audit deny /sys/kernel/security/apparmor/matching rwxl,
audit deny /sys/kernel/security/apparmor/.* rwxl,
/sys/kernel/security/apparmor/profiles r,
/usr/lib/libvirt/* PUxr,
/usr/{lib,lib64}/libvirt/* PUxr,
/etc/libvirt/hooks/** rmix,
/etc/xen/scripts/** rmix,