Unverified Commit 296f7311 by Wolfgang Bumiller Committed by Christian Brauner

apparmor: update current profiles

remove cgmanager rules and add fstype=cgroup2 variants for the existing fstype=cgroup rules Signed-off-by: 's avatarWolfgang Bumiller <w.bumiller@proxmox.com>
parent 99b7f9db
...@@ -85,7 +85,6 @@ ...@@ -85,7 +85,6 @@
mount options=(rw, nosuid, nodev, noexec, remount) -> /sys/, mount options=(rw, nosuid, nodev, noexec, remount) -> /sys/,
deny /sys/firmware/efi/efivars/** rwklx, deny /sys/firmware/efi/efivars/** rwklx,
deny /sys/kernel/security/** rwklx, deny /sys/kernel/security/** rwklx,
mount options=(move) /sys/fs/cgroup/cgmanager/ -> /sys/fs/cgroup/cgmanager.lower/,
mount options=(ro, nosuid, nodev, noexec, remount, strictatime) -> /sys/fs/cgroup/, mount options=(ro, nosuid, nodev, noexec, remount, strictatime) -> /sys/fs/cgroup/,
# deny reads from debugfs # deny reads from debugfs
......
...@@ -9,4 +9,5 @@ profile lxc-container-default-cgns flags=(attach_disconnected,mediate_deleted) { ...@@ -9,4 +9,5 @@ profile lxc-container-default-cgns flags=(attach_disconnected,mediate_deleted) {
# the newinstance option (but, right now, we don't). # the newinstance option (but, right now, we don't).
deny mount fstype=devpts, deny mount fstype=devpts,
mount fstype=cgroup -> /sys/fs/cgroup/**, mount fstype=cgroup -> /sys/fs/cgroup/**,
mount fstype=cgroup2 -> /sys/fs/cgroup/**,
} }
...@@ -11,4 +11,5 @@ profile lxc-container-default-with-nesting flags=(attach_disconnected,mediate_de ...@@ -11,4 +11,5 @@ profile lxc-container-default-with-nesting flags=(attach_disconnected,mediate_de
mount fstype=sysfs -> /var/cache/lxc/**, mount fstype=sysfs -> /var/cache/lxc/**,
mount options=(rw,bind), mount options=(rw,bind),
mount fstype=cgroup -> /sys/fs/cgroup/**, mount fstype=cgroup -> /sys/fs/cgroup/**,
mount fstype=cgroup2 -> /sys/fs/cgroup/**,
} }
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment