mirror of
https://gitlab.com/apparmor/apparmor
synced 2025-09-03 07:45:50 +00:00
usr.sbin.sshd: add cgroup-related rules
This commit is contained in:
@@ -70,6 +70,9 @@
|
|||||||
owner @{PROC}/@{pid}/oom_adj rw,
|
owner @{PROC}/@{pid}/oom_adj rw,
|
||||||
owner @{PROC}/@{pid}/oom_score_adj rw,
|
owner @{PROC}/@{pid}/oom_score_adj rw,
|
||||||
|
|
||||||
|
/sys/fs/cgroup/*/user/*/[0-9]*/ rw,
|
||||||
|
/sys/fs/cgroup/systemd/user.slice/user-[0-9]*.slice/session-c[0-9]*.scope/ rw,
|
||||||
|
|
||||||
# should only be here for use in non-change-hat openssh
|
# should only be here for use in non-change-hat openssh
|
||||||
# duplicated from EXEC hat (+r)
|
# duplicated from EXEC hat (+r)
|
||||||
/bin/ash Uxr,
|
/bin/ash Uxr,
|
||||||
|
Reference in New Issue
Block a user