mirror of
https://gitlab.com/apparmor/apparmor
synced 2025-09-01 06:45:38 +00:00
Merge unprivileged_userns profile: Allow full file system access
Fixes https://gitlab.com/apparmor/apparmor/-/issues/505 The profile previously permitted access to `/**`, which excludes the root directory (`/`). This commit also gives `/` access, aligning with the intended behavior. Signed-off-by: Maxime Bélair <maxime.belair@canonical.com> Closes #505 MR: https://gitlab.com/apparmor/apparmor/-/merge_requests/1626 Approved-by: Georgia Garcia <georgia.garcia@canonical.com> Merged-by: John Johansen <john@jjmx.net>
This commit is contained in:
@@ -13,7 +13,7 @@ profile unprivileged_userns {
|
|||||||
allow network,
|
allow network,
|
||||||
allow signal,
|
allow signal,
|
||||||
allow dbus,
|
allow dbus,
|
||||||
allow file rwlkm /**,
|
allow file rwlkm /{,**},
|
||||||
allow unix,
|
allow unix,
|
||||||
allow mqueue,
|
allow mqueue,
|
||||||
allow ptrace,
|
allow ptrace,
|
||||||
|
Reference in New Issue
Block a user