mirror of
https://gitlab.com/libvirt/libvirt.git
synced 2025-01-03 03:25:20 +00:00
AppArmor policy: support merged-/usr.
Acked-by: Christian Ehrhardt <christian.ehrhardt@canonical.co>
This commit is contained in:
parent
e36a0e0cde
commit
de79efdeb8
@ -136,12 +136,12 @@
|
|||||||
/usr/{lib,lib64}/qemu/block-rbd.so mr,
|
/usr/{lib,lib64}/qemu/block-rbd.so mr,
|
||||||
|
|
||||||
# for save and resume
|
# for save and resume
|
||||||
/bin/dash rmix,
|
/{usr/,}bin/dash rmix,
|
||||||
/bin/dd rmix,
|
/{usr/,}bin/dd rmix,
|
||||||
/bin/cat rmix,
|
/{usr/,}bin/cat rmix,
|
||||||
|
|
||||||
# for restore
|
# for restore
|
||||||
/bin/bash rmix,
|
/{usr/,}bin/bash rmix,
|
||||||
|
|
||||||
# for usb access
|
# for usb access
|
||||||
/dev/bus/usb/ r,
|
/dev/bus/usb/ r,
|
||||||
|
@ -21,7 +21,7 @@ profile virt-aa-helper /usr/{lib,lib64}/libvirt/virt-aa-helper {
|
|||||||
/sys/devices/** r,
|
/sys/devices/** r,
|
||||||
|
|
||||||
/usr/{lib,lib64}/libvirt/virt-aa-helper mr,
|
/usr/{lib,lib64}/libvirt/virt-aa-helper mr,
|
||||||
/sbin/apparmor_parser Ux,
|
/{usr/,}sbin/apparmor_parser Ux,
|
||||||
|
|
||||||
/etc/apparmor.d/libvirt/* r,
|
/etc/apparmor.d/libvirt/* r,
|
||||||
/etc/apparmor.d/libvirt/libvirt-[0-9a-f]*-[0-9a-f]*-[0-9a-f]*-[0-9a-f]*-[0-9a-f]* rw,
|
/etc/apparmor.d/libvirt/libvirt-[0-9a-f]*-[0-9a-f]*-[0-9a-f]*-[0-9a-f]*-[0-9a-f]* rw,
|
||||||
|
@ -47,12 +47,12 @@
|
|||||||
/usr/bin/* PUx,
|
/usr/bin/* PUx,
|
||||||
/usr/sbin/virtlogd pix,
|
/usr/sbin/virtlogd pix,
|
||||||
/usr/sbin/* PUx,
|
/usr/sbin/* PUx,
|
||||||
/lib/udev/scsi_id PUx,
|
/{usr/,}lib/udev/scsi_id PUx,
|
||||||
/usr/{lib,lib64}/xen-common/bin/xen-toolstack PUx,
|
/usr/{lib,lib64}/xen-common/bin/xen-toolstack PUx,
|
||||||
/usr/{lib,lib64}/xen/bin/* Ux,
|
/usr/{lib,lib64}/xen/bin/* Ux,
|
||||||
|
|
||||||
# force the use of virt-aa-helper
|
# force the use of virt-aa-helper
|
||||||
audit deny /sbin/apparmor_parser rwxl,
|
audit deny /{usr/,}sbin/apparmor_parser rwxl,
|
||||||
audit deny /etc/apparmor.d/libvirt/** wxl,
|
audit deny /etc/apparmor.d/libvirt/** wxl,
|
||||||
audit deny /sys/kernel/security/apparmor/features rwxl,
|
audit deny /sys/kernel/security/apparmor/features rwxl,
|
||||||
audit deny /sys/kernel/security/apparmor/matching rwxl,
|
audit deny /sys/kernel/security/apparmor/matching rwxl,
|
||||||
|
Loading…
Reference in New Issue
Block a user