build: update full system policy setup.

This commit is contained in:
Alexandre Pujol 2023-11-11 20:25:27 +00:00
parent 5760c0129c
commit 3b42cc0ca7
Failed to generate hash of commit

View file

@ -173,11 +173,10 @@ func SetFlags() error {
return nil return nil
} }
// Set AppArmor for full system policy // Set AppArmor for (experimental) full system policy.
// See https://gitlab.com/apparmor/apparmor/-/wikis/FullSystemPolicy // See https://apparmor.pujol.io/development/structure/#full-system-policy
// https://gitlab.com/apparmor/apparmor/-/wikis/AppArmorInSystemd#early-policy-loads
func SetFullSystemPolicy() error { func SetFullSystemPolicy() error {
for _, name := range []string{"init", "systemd"} { for _, name := range []string{"systemd", "systemd-user"} {
err := paths.New("apparmor.d/groups/_full/" + name).CopyTo(RootApparmord.Join(name)) err := paths.New("apparmor.d/groups/_full/" + name).CopyTo(RootApparmord.Join(name))
if err != nil { if err != nil {
return err return err