aboutgitcodebugslistschat
path: root/contrib/apparmor/abstractions/pasta
diff options
context:
space:
mode:
authorStefano Brivio <sbrivio@redhat.com>2023-09-06 21:46:14 +0200
committerStefano Brivio <sbrivio@redhat.com>2023-09-07 00:31:35 +0200
commitabf5ef6c22d2e6fce0f0abe398a2c18b70ca6290 (patch)
treedf5fe92e4a273f76b3a358f26323c03634f788fb /contrib/apparmor/abstractions/pasta
parente2ad420fa268533628c32acab35fb66f187cef39 (diff)
downloadpasst-abf5ef6c22d2e6fce0f0abe398a2c18b70ca6290.tar
passt-abf5ef6c22d2e6fce0f0abe398a2c18b70ca6290.tar.gz
passt-abf5ef6c22d2e6fce0f0abe398a2c18b70ca6290.tar.bz2
passt-abf5ef6c22d2e6fce0f0abe398a2c18b70ca6290.tar.lz
passt-abf5ef6c22d2e6fce0f0abe398a2c18b70ca6290.tar.xz
passt-abf5ef6c22d2e6fce0f0abe398a2c18b70ca6290.tar.zst
passt-abf5ef6c22d2e6fce0f0abe398a2c18b70ca6290.zip
apparmor: Allow pasta to remount /proc, access entries under its own copy
Since commit b0e450aa8500 ("pasta: Detach mount namespace, (re)mount procfs before spawning command"), we need to explicitly permit mount of /proc, and access to entries under /proc/PID/net (after remount, that's what AppArmor sees as path). Fixes: b0e450aa8500 ("pasta: Detach mount namespace, (re)mount procfs before spawning command") Signed-off-by: Stefano Brivio <sbrivio@redhat.com>
Diffstat (limited to 'contrib/apparmor/abstractions/pasta')
-rw-r--r--contrib/apparmor/abstractions/pasta7
1 files changed, 7 insertions, 0 deletions
diff --git a/contrib/apparmor/abstractions/pasta b/contrib/apparmor/abstractions/pasta
index 9cba25a..05c5d46 100644
--- a/contrib/apparmor/abstractions/pasta
+++ b/contrib/apparmor/abstractions/pasta
@@ -15,11 +15,18 @@
include <abstractions/passt>
+ mount "" -> "/proc/",
+
@{PROC}/net/tcp r, # procfs_scan_listen(), util.c
@{PROC}/net/tcp6 r,
@{PROC}/net/udp r,
@{PROC}/net/udp6 r,
+ @{PROC}/@{pid}/net/tcp r, # procfs_scan_listen(), util.c
+ @{PROC}/@{pid}/net/tcp6 r,
+ @{PROC}/@{pid}/net/udp r,
+ @{PROC}/@{pid}/net/udp6 r,
+
@{run}/user/@{uid}/netns/* r, # pasta_open_ns(), pasta.c
@{PROC}/[0-9]*/ns/net r, # pasta_wait_for_ns(),