Skip to content
Snippets Groups Projects
Commit d6f16a9d authored by Dylan Aïssi's avatar Dylan Aïssi
Browse files

apparmor: fix rule for /proc/*/task/*/comm


`apparmor-pipewire` test currently fails with following AppArmor audit log:
```
# ====
# profile:/usr/bin/pipewire
# sdmode:REJECTING
# denied_mask:wr
# operation:open
# name:/proc/3070/task/3079/comm
# request_mask:wr
```

Signed-off-by: default avatarDylan Aïssi <dylan.aissi@collabora.com>
parent f1540adf
No related branches found
No related tags found
2 merge requests!49Backport Debian Bullseye Security/Updates,!46apparmor: fix rule for /proc/*/task/*/comm
......@@ -26,6 +26,7 @@ profile /usr/bin/pipewire {
owner @{PROC}/*/stat r,
owner @{PROC}/*/fd/ r,
owner @{PROC}/*/fd/* r,
owner @{PROC}/*/task/*/comm rw,
# This seems to be mediated as ptrace(trace), ptrace(traceby).
ptrace (read),
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment