Skip to content
Snippets Groups Projects
Commit 0e1d9c67 authored by Frederic Danis's avatar Frederic Danis
Browse files

AppArmor: Allow access to mount related files


apparmor-session-lockdown-no-deny test returns the following events:
$ sudo journalctl -b -t audit -o cat | aa_log_extract_tokens.sh DENIED
====
profile:/usr/bin/prestwood
apparmor:DENIED
denied_mask:r
operation:open
name:/proc/905/mountinfo
requested_mask:r
====
profile:/usr/bin/prestwood
apparmor:DENIED
denied_mask:r
operation:open
name:/etc/fstab
requested_mask:r
====
profile:/usr/bin/prestwood
apparmor:DENIED
denied_mask:r
operation:open
name:/proc/905/mountinfo
requested_mask:r
====
profile:/usr/bin/prestwood
apparmor:DENIED
denied_mask:r
operation:open
name:/proc/905/mounts
requested_mask:r

Signed-off-by: default avatarFrédéric Danis <frederic.danis@collabora.com>
parent 26947914
No related branches found
No related tags found
4 merge requests!6Merge changes from apertis/v2019-updates into apertis/v2019,!4Land latest changes to v2020,!3Land latest changes to v2019-updates,!1AppArmor: Allow access to mount related files
......@@ -28,4 +28,7 @@
dbus (send, receive) bus=session peer=(label=/usr/lib/gvfs/gvfs*),
/run/systemd/journal/{socket,stdout} rw,
/proc/@{pid}/mountinfo r,
/proc/@{pid}/mounts r,
/etc/fstab r,
}
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment