Skip to content
Snippets Groups Projects

AppArmor: Allow access to mount related files

Merged Frederic Danis requested to merge wip/fdanis/6233 into apertis/v2021dev1

apparmor-session-lockdown-no-deny test returns the following events:

$ sudo journalctl -b -t audit -o cat | aa_log_extract_tokens.sh DENIED
====
profile:/usr/bin/prestwood
apparmor:DENIED
denied_mask:r
operation:open
name:/proc/905/mountinfo
requested_mask:r
====
profile:/usr/bin/prestwood
apparmor:DENIED
denied_mask:r
operation:open
name:/etc/fstab
requested_mask:r
====
profile:/usr/bin/prestwood
apparmor:DENIED
denied_mask:r
operation:open
name:/proc/905/mountinfo
requested_mask:r
====
profile:/usr/bin/prestwood
apparmor:DENIED
denied_mask:r
operation:open
name:/proc/905/mounts
requested_mask:r

Signed-off-by: Frédéric Danis frederic.danis@collabora.com

Edited by Frederic Danis

Merge request reports

Loading
Loading

Activity

Filter activity
  • Approvals
  • Assignees & reviewers
  • Comments (from bots)
  • Comments (from users)
  • Commits & branches
  • Edits
  • Labels
  • Lock status
  • Mentions
  • Merge request status
  • Tracking
Please register or sign in to reply
Loading