提交 de79efde 编写于 作者: I intrigeri 提交者: Daniel P. Berrange

AppArmor policy: support merged-/usr.

Acked-by: NChristian Ehrhardt <christian.ehrhardt@canonical.co>
上级 e36a0e0c
...@@ -136,12 +136,12 @@ ...@@ -136,12 +136,12 @@
/usr/{lib,lib64}/qemu/block-rbd.so mr, /usr/{lib,lib64}/qemu/block-rbd.so mr,
# for save and resume # for save and resume
/bin/dash rmix, /{usr/,}bin/dash rmix,
/bin/dd rmix, /{usr/,}bin/dd rmix,
/bin/cat rmix, /{usr/,}bin/cat rmix,
# for restore # for restore
/bin/bash rmix, /{usr/,}bin/bash rmix,
# for usb access # for usb access
/dev/bus/usb/ r, /dev/bus/usb/ r,
......
...@@ -21,7 +21,7 @@ profile virt-aa-helper /usr/{lib,lib64}/libvirt/virt-aa-helper { ...@@ -21,7 +21,7 @@ profile virt-aa-helper /usr/{lib,lib64}/libvirt/virt-aa-helper {
/sys/devices/** r, /sys/devices/** r,
/usr/{lib,lib64}/libvirt/virt-aa-helper mr, /usr/{lib,lib64}/libvirt/virt-aa-helper mr,
/sbin/apparmor_parser Ux, /{usr/,}sbin/apparmor_parser Ux,
/etc/apparmor.d/libvirt/* r, /etc/apparmor.d/libvirt/* r,
/etc/apparmor.d/libvirt/libvirt-[0-9a-f]*-[0-9a-f]*-[0-9a-f]*-[0-9a-f]*-[0-9a-f]* rw, /etc/apparmor.d/libvirt/libvirt-[0-9a-f]*-[0-9a-f]*-[0-9a-f]*-[0-9a-f]*-[0-9a-f]* rw,
......
...@@ -47,12 +47,12 @@ ...@@ -47,12 +47,12 @@
/usr/bin/* PUx, /usr/bin/* PUx,
/usr/sbin/virtlogd pix, /usr/sbin/virtlogd pix,
/usr/sbin/* PUx, /usr/sbin/* PUx,
/lib/udev/scsi_id PUx, /{usr/,}lib/udev/scsi_id PUx,
/usr/{lib,lib64}/xen-common/bin/xen-toolstack PUx, /usr/{lib,lib64}/xen-common/bin/xen-toolstack PUx,
/usr/{lib,lib64}/xen/bin/* Ux, /usr/{lib,lib64}/xen/bin/* Ux,
# force the use of virt-aa-helper # force the use of virt-aa-helper
audit deny /sbin/apparmor_parser rwxl, audit deny /{usr/,}sbin/apparmor_parser rwxl,
audit deny /etc/apparmor.d/libvirt/** wxl, audit deny /etc/apparmor.d/libvirt/** wxl,
audit deny /sys/kernel/security/apparmor/features rwxl, audit deny /sys/kernel/security/apparmor/features rwxl,
audit deny /sys/kernel/security/apparmor/matching rwxl, audit deny /sys/kernel/security/apparmor/matching rwxl,
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册