Add ptrace subprofile

This commit is contained in:
Jeroen Rijken 2022-07-21 16:03:54 +02:00 committed by Alex
parent d6d9c943ae
commit 61eab33cd8

View file

@ -24,8 +24,7 @@ profile k3s @{exec_path} flags=(complain) {
capability sys_resource,
ptrace peer=@{profile_name},
ptrace (read) peer=unconfined,
ptrace (read) peer=cri-containerd.apparmor.d,
ptrace (read) peer={cri-containerd.apparmor.d,k3s//xtables-nft-multi,unconfined},
network inet dgram,
network inet6 dgram,
@ -149,6 +148,7 @@ profile k3s @{exec_path} flags=(complain) {
@{sys}/module/apparmor/parameters/enabled r,
/dev/kmsg r,
/dev/pts/[0-9]* rw,
profile xtables-nft-multi flags=(complain) {
include <abstractions/base>