aboutgitcodebugslistschat
path: root/contrib/apparmor/usr.bin.pasta
diff options
context:
space:
mode:
authorStefano Brivio <sbrivio@redhat.com>2024-05-23 13:14:22 +0200
committerStefano Brivio <sbrivio@redhat.com>2024-05-23 16:44:21 +0200
commit765eb0bf1651d20ca319eeb8b41ff35f52f2a29c (patch)
treea45c9318bb134f6fba7e8efd9ea1aade6b0c0b60 /contrib/apparmor/usr.bin.pasta
parent0608ec42f2c134b2b72f4939a722ff3433dbaae0 (diff)
downloadpasst-765eb0bf1651d20ca319eeb8b41ff35f52f2a29c.tar
passt-765eb0bf1651d20ca319eeb8b41ff35f52f2a29c.tar.gz
passt-765eb0bf1651d20ca319eeb8b41ff35f52f2a29c.tar.bz2
passt-765eb0bf1651d20ca319eeb8b41ff35f52f2a29c.tar.lz
passt-765eb0bf1651d20ca319eeb8b41ff35f52f2a29c.tar.xz
passt-765eb0bf1651d20ca319eeb8b41ff35f52f2a29c.tar.zst
passt-765eb0bf1651d20ca319eeb8b41ff35f52f2a29c.zip
apparmor: Fix comments after PID file and AF_UNIX socket creation refactoring2024_05_23.765eb0b
Now: - we don't open the PID file in main() anymore - PID file and AF_UNIX socket are opened by pidfile_open() and tap_sock_unix_open() - write_pidfile() becomes pidfile_write() Reported-by: Richard W.M. Jones <rjones@redhat.com> Signed-off-by: Stefano Brivio <sbrivio@redhat.com> Acked-by: Richard W.M. Jones <rjones@redhat.com>
Diffstat (limited to 'contrib/apparmor/usr.bin.pasta')
-rw-r--r--contrib/apparmor/usr.bin.pasta9
1 files changed, 6 insertions, 3 deletions
diff --git a/contrib/apparmor/usr.bin.pasta b/contrib/apparmor/usr.bin.pasta
index bdfeb71..2483968 100644
--- a/contrib/apparmor/usr.bin.pasta
+++ b/contrib/apparmor/usr.bin.pasta
@@ -19,10 +19,13 @@ profile pasta /usr/bin/pasta{,.avx2} flags=(attach_disconnected) {
include <abstractions/pasta>
# Alternatively: include <abstractions/user-tmp>
- /tmp/** rw, # tap_sock_unix_init(), pcap(),
- # write_pidfile(),
+ /tmp/** rw, # tap_sock_unix_open(),
+ # tap_sock_unix_init(), pcap(),
+ # pidfile_open(),
+ # pidfile_write(),
# logfile_init(),
# pasta_open_ns()
- owner @{HOME}/** w, # pcap(), write_pidfile()
+ owner @{HOME}/** w, # pcap(), pidfile_open(),
+ # pidfile_write()
}