diff options
author | Stefano Brivio <sbrivio@redhat.com> | 2023-09-06 21:46:14 +0200 |
---|---|---|
committer | Stefano Brivio <sbrivio@redhat.com> | 2023-09-07 00:31:35 +0200 |
commit | abf5ef6c22d2e6fce0f0abe398a2c18b70ca6290 (patch) | |
tree | df5fe92e4a273f76b3a358f26323c03634f788fb | |
parent | e2ad420fa268533628c32acab35fb66f187cef39 (diff) | |
download | passt-abf5ef6c22d2e6fce0f0abe398a2c18b70ca6290.tar passt-abf5ef6c22d2e6fce0f0abe398a2c18b70ca6290.tar.gz passt-abf5ef6c22d2e6fce0f0abe398a2c18b70ca6290.tar.bz2 passt-abf5ef6c22d2e6fce0f0abe398a2c18b70ca6290.tar.lz passt-abf5ef6c22d2e6fce0f0abe398a2c18b70ca6290.tar.xz passt-abf5ef6c22d2e6fce0f0abe398a2c18b70ca6290.tar.zst passt-abf5ef6c22d2e6fce0f0abe398a2c18b70ca6290.zip |
apparmor: Allow pasta to remount /proc, access entries under its own copy
Since commit b0e450aa8500 ("pasta: Detach mount namespace, (re)mount
procfs before spawning command"), we need to explicitly permit mount
of /proc, and access to entries under /proc/PID/net (after remount,
that's what AppArmor sees as path).
Fixes: b0e450aa8500 ("pasta: Detach mount namespace, (re)mount procfs before spawning command")
Signed-off-by: Stefano Brivio <sbrivio@redhat.com>
-rw-r--r-- | contrib/apparmor/abstractions/pasta | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/contrib/apparmor/abstractions/pasta b/contrib/apparmor/abstractions/pasta index 9cba25a..05c5d46 100644 --- a/contrib/apparmor/abstractions/pasta +++ b/contrib/apparmor/abstractions/pasta @@ -15,11 +15,18 @@ include <abstractions/passt> + mount "" -> "/proc/", + @{PROC}/net/tcp r, # procfs_scan_listen(), util.c @{PROC}/net/tcp6 r, @{PROC}/net/udp r, @{PROC}/net/udp6 r, + @{PROC}/@{pid}/net/tcp r, # procfs_scan_listen(), util.c + @{PROC}/@{pid}/net/tcp6 r, + @{PROC}/@{pid}/net/udp r, + @{PROC}/@{pid}/net/udp6 r, + @{run}/user/@{uid}/netns/* r, # pasta_open_ns(), pasta.c @{PROC}/[0-9]*/ns/net r, # pasta_wait_for_ns(), |