From 765eb0bf1651d20ca319eeb8b41ff35f52f2a29c Mon Sep 17 00:00:00 2001 From: Stefano Brivio Date: Thu, 23 May 2024 13:14:22 +0200 Subject: apparmor: Fix comments after PID file and AF_UNIX socket creation refactoring Now: - we don't open the PID file in main() anymore - PID file and AF_UNIX socket are opened by pidfile_open() and tap_sock_unix_open() - write_pidfile() becomes pidfile_write() Reported-by: Richard W.M. Jones Signed-off-by: Stefano Brivio Acked-by: Richard W.M. Jones --- contrib/apparmor/usr.bin.pasta | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) (limited to 'contrib/apparmor/usr.bin.pasta') diff --git a/contrib/apparmor/usr.bin.pasta b/contrib/apparmor/usr.bin.pasta index bdfeb71..2483968 100644 --- a/contrib/apparmor/usr.bin.pasta +++ b/contrib/apparmor/usr.bin.pasta @@ -19,10 +19,13 @@ profile pasta /usr/bin/pasta{,.avx2} flags=(attach_disconnected) { include # Alternatively: include - /tmp/** rw, # tap_sock_unix_init(), pcap(), - # write_pidfile(), + /tmp/** rw, # tap_sock_unix_open(), + # tap_sock_unix_init(), pcap(), + # pidfile_open(), + # pidfile_write(), # logfile_init(), # pasta_open_ns() - owner @{HOME}/** w, # pcap(), write_pidfile() + owner @{HOME}/** w, # pcap(), pidfile_open(), + # pidfile_write() } -- cgit v1.2.3