mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2024-11-15 16:03:51 +01:00
Apply suggestions from code review
This commit is contained in:
parent
8a13d71edb
commit
6e1e7dc32b
@ -43,7 +43,7 @@ profile containerd @{exec_path} flags=(attach_disconnected) {
|
|||||||
@{run}/netns/ w,
|
@{run}/netns/ w,
|
||||||
@{run}/netns/cni-@{uuid} rw,
|
@{run}/netns/cni-@{uuid} rw,
|
||||||
/var/lib/cni/results/cni-loopback-@{uuid}-lo l,
|
/var/lib/cni/results/cni-loopback-@{uuid}-lo l,
|
||||||
@{PROC}/@{pid}/task/[0-9]*/ns/net rw,
|
@{PROC}/@{pid}/task/@{tid}/ns/net rw,
|
||||||
|
|
||||||
/var/lib/containerd/{,**} rwk,
|
/var/lib/containerd/{,**} rwk,
|
||||||
/var/lib/docker/containerd/{,**} rwk,
|
/var/lib/docker/containerd/{,**} rwk,
|
||||||
@ -63,7 +63,7 @@ profile containerd @{exec_path} flags=(attach_disconnected) {
|
|||||||
@{sys}/kernel/security/apparmor/profiles r,
|
@{sys}/kernel/security/apparmor/profiles r,
|
||||||
@{sys}/module/apparmor/parameters/enabled r,
|
@{sys}/module/apparmor/parameters/enabled r,
|
||||||
/tmp/cri-containerd.apparmor.d[0-9]* rwl,
|
/tmp/cri-containerd.apparmor.d[0-9]* rwl,
|
||||||
/usr/sbin/apparmor_parser Px,
|
/{usr/,}{s,}bin/apparmor_parser rPx,
|
||||||
|
|
||||||
include if exists <local/containerd>
|
include if exists <local/containerd>
|
||||||
}
|
}
|
||||||
|
Loading…
Reference in New Issue
Block a user