mirror of
https://gitlab.com/libvirt/libvirt.git
synced 2025-01-03 11:35:19 +00:00
Teach AppArmor, that /usr/lib64 may exist.
The apparmor profiles forgot about /usr/lib64 folders, just add lib64 as a possible alternative to lib in the paths
This commit is contained in:
parent
703ef9667a
commit
30c6aecc44
@ -111,7 +111,7 @@
|
|||||||
/usr/bin/qemu-sparc32plus rmix,
|
/usr/bin/qemu-sparc32plus rmix,
|
||||||
/usr/bin/qemu-sparc64 rmix,
|
/usr/bin/qemu-sparc64 rmix,
|
||||||
/usr/bin/qemu-x86_64 rmix,
|
/usr/bin/qemu-x86_64 rmix,
|
||||||
/usr/lib/qemu/block-curl.so mr,
|
/usr/{lib,lib64}/qemu/block-curl.so mr,
|
||||||
|
|
||||||
# for save and resume
|
# for save and resume
|
||||||
/bin/dash rmix,
|
/bin/dash rmix,
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
# Last Modified: Mon Apr 5 15:10:27 2010
|
# Last Modified: Mon Apr 5 15:10:27 2010
|
||||||
#include <tunables/global>
|
#include <tunables/global>
|
||||||
|
|
||||||
/usr/lib/libvirt/virt-aa-helper {
|
profile virt-aa-helper /usr/{lib,lib64}/libvirt/virt-aa-helper {
|
||||||
#include <abstractions/base>
|
#include <abstractions/base>
|
||||||
|
|
||||||
# needed for searching directories
|
# needed for searching directories
|
||||||
@ -20,7 +20,7 @@
|
|||||||
/sys/devices/ r,
|
/sys/devices/ r,
|
||||||
/sys/devices/** r,
|
/sys/devices/** r,
|
||||||
|
|
||||||
/usr/lib/libvirt/virt-aa-helper mr,
|
/usr/{lib,lib64}/libvirt/virt-aa-helper mr,
|
||||||
/sbin/apparmor_parser Ux,
|
/sbin/apparmor_parser Ux,
|
||||||
|
|
||||||
/etc/apparmor.d/libvirt/* r,
|
/etc/apparmor.d/libvirt/* r,
|
||||||
|
@ -44,7 +44,7 @@
|
|||||||
/usr/bin/* PUx,
|
/usr/bin/* PUx,
|
||||||
/usr/sbin/* PUx,
|
/usr/sbin/* PUx,
|
||||||
/lib/udev/scsi_id PUx,
|
/lib/udev/scsi_id PUx,
|
||||||
/usr/lib/xen-common/bin/xen-toolstack PUx,
|
/usr/{lib,lib64}/xen-common/bin/xen-toolstack PUx,
|
||||||
|
|
||||||
# force the use of virt-aa-helper
|
# force the use of virt-aa-helper
|
||||||
audit deny /sbin/apparmor_parser rwxl,
|
audit deny /sbin/apparmor_parser rwxl,
|
||||||
@ -53,7 +53,7 @@
|
|||||||
audit deny /sys/kernel/security/apparmor/matching rwxl,
|
audit deny /sys/kernel/security/apparmor/matching rwxl,
|
||||||
audit deny /sys/kernel/security/apparmor/.* rwxl,
|
audit deny /sys/kernel/security/apparmor/.* rwxl,
|
||||||
/sys/kernel/security/apparmor/profiles r,
|
/sys/kernel/security/apparmor/profiles r,
|
||||||
/usr/lib/libvirt/* PUxr,
|
/usr/{lib,lib64}/libvirt/* PUxr,
|
||||||
/etc/libvirt/hooks/** rmix,
|
/etc/libvirt/hooks/** rmix,
|
||||||
/etc/xen/scripts/** rmix,
|
/etc/xen/scripts/** rmix,
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user