diff options
author | Stefano Brivio <sbrivio@redhat.com> | 2023-09-06 22:55:22 +0200 |
---|---|---|
committer | Stefano Brivio <sbrivio@redhat.com> | 2023-09-07 00:31:35 +0200 |
commit | 63a8302961a421a67d38c52285be3c2ef149e6cc (patch) | |
tree | 384ac04edfece1f9622faad94be6801afbb21e23 /test/README.md | |
parent | abf5ef6c22d2e6fce0f0abe398a2c18b70ca6290 (diff) | |
download | passt-63a8302961a421a67d38c52285be3c2ef149e6cc.tar passt-63a8302961a421a67d38c52285be3c2ef149e6cc.tar.gz passt-63a8302961a421a67d38c52285be3c2ef149e6cc.tar.bz2 passt-63a8302961a421a67d38c52285be3c2ef149e6cc.tar.lz passt-63a8302961a421a67d38c52285be3c2ef149e6cc.tar.xz passt-63a8302961a421a67d38c52285be3c2ef149e6cc.tar.zst passt-63a8302961a421a67d38c52285be3c2ef149e6cc.zip |
apparmor: Add pasta's own profile
If pasta and pasta.avx2 are hard links to passt and passt.avx2,
AppArmor will attach their own profiles on execution, and we can
restrict passt's profile to what it actually needs. Note that pasta
needs to access all the resources that passt needs, so the pasta
abstraction still includes passt's one.
I plan to push the adaptation required for the Debian package in
commit 5bb812e79143 ("debian/rules: Override pasta symbolic links
with hard links"), on Salsa. If other distributions need to support
AppArmor profiles they can follow a similar approach.
The profile itself will be installed, there, via dh_apparmor, in a
separate commit, b52557fedcb1 ("debian/rules: Install new pasta
profile using dh_apparmor").
Signed-off-by: Stefano Brivio <sbrivio@redhat.com>
Diffstat (limited to 'test/README.md')
0 files changed, 0 insertions, 0 deletions