aboutgitcodebugslistschat
diff options
context:
space:
mode:
-rw-r--r--contrib/apparmor/abstractions/pasta7
1 files changed, 7 insertions, 0 deletions
diff --git a/contrib/apparmor/abstractions/pasta b/contrib/apparmor/abstractions/pasta
index 9cba25a..05c5d46 100644
--- a/contrib/apparmor/abstractions/pasta
+++ b/contrib/apparmor/abstractions/pasta
@@ -15,11 +15,18 @@
include <abstractions/passt>
+ mount "" -> "/proc/",
+
@{PROC}/net/tcp r, # procfs_scan_listen(), util.c
@{PROC}/net/tcp6 r,
@{PROC}/net/udp r,
@{PROC}/net/udp6 r,
+ @{PROC}/@{pid}/net/tcp r, # procfs_scan_listen(), util.c
+ @{PROC}/@{pid}/net/tcp6 r,
+ @{PROC}/@{pid}/net/udp r,
+ @{PROC}/@{pid}/net/udp6 r,
+
@{run}/user/@{uid}/netns/* r, # pasta_open_ns(), pasta.c
@{PROC}/[0-9]*/ns/net r, # pasta_wait_for_ns(),