Properly update the generated apparmor profiles

Some changes happened but the final profiles weren't generated... Signed-off-by: 's avatarStéphane Graber <stgraber@ubuntu.com>
parent eab570bc
...@@ -62,6 +62,10 @@ ...@@ -62,6 +62,10 @@
# allow bind mount of /lib/init/fstab for lxcguest # allow bind mount of /lib/init/fstab for lxcguest
mount options=(rw, bind) /lib/init/fstab.lxc/ -> /lib/init/fstab/, mount options=(rw, bind) /lib/init/fstab.lxc/ -> /lib/init/fstab/,
# allow bind mounts of /run/{,lock} to /var/run/{,lock}
mount options=(rw, bind) /run/ -> /var/run/,
mount options=(rw, bind) /run/lock/ -> /var/lock/,
# deny writes in /proc/sys/fs but allow binfmt_misc to be mounted # deny writes in /proc/sys/fs but allow binfmt_misc to be mounted
mount fstype=binfmt_misc -> /proc/sys/fs/binfmt_misc/, mount fstype=binfmt_misc -> /proc/sys/fs/binfmt_misc/,
deny @{PROC}/sys/fs/** wklx, deny @{PROC}/sys/fs/** wklx,
...@@ -83,9 +87,11 @@ ...@@ -83,9 +87,11 @@
deny mount fstype=debugfs -> /var/lib/ureadahead/debugfs/, deny mount fstype=debugfs -> /var/lib/ureadahead/debugfs/,
mount fstype=proc -> /proc/, mount fstype=proc -> /proc/,
mount fstype=sysfs -> /sys/, mount fstype=sysfs -> /sys/,
mount options=(rw, nosuid, nodev, noexec, remount) -> /sys/,
deny /sys/firmware/efi/efivars/** rwklx, deny /sys/firmware/efi/efivars/** rwklx,
deny /sys/kernel/security/** rwklx, deny /sys/kernel/security/** rwklx,
mount options=(move) /sys/fs/cgroup/cgmanager/ -> /sys/fs/cgroup/cgmanager.lower/, mount options=(move) /sys/fs/cgroup/cgmanager/ -> /sys/fs/cgroup/cgmanager.lower/,
mount options=(ro, nosuid, nodev, noexec, remount, strictatime) -> /sys/fs/cgroup/,
# generated by: lxc-generate-aa-rules.py container-rules.base # generated by: lxc-generate-aa-rules.py container-rules.base
deny /proc/sys/[^kn]*{,/**} wklx, deny /proc/sys/[^kn]*{,/**} wklx,
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment