mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2025-02-03 08:45:06 +01:00
fix(profile): minor fixes.
This commit is contained in:
parent
194d18191e
commit
b4bcb2f16e
2 changed files with 6 additions and 4 deletions
|
@ -20,11 +20,13 @@ profile ip @{exec_path} flags=(attach_disconnected) {
|
|||
|
||||
network netlink raw,
|
||||
|
||||
mount options=(rw, rshared) -> @{run}/netns/,
|
||||
mount options=(rw, rslave) -> /,
|
||||
mount fstype=sysfs -> /sys/,
|
||||
mount options=(rw bind) / -> @{run}/netns/*,
|
||||
mount options=(rw rbind) @{run}/netns/ -> @{run}/netns/,
|
||||
mount options=(rw, bind) @{att}/ -> @{run}/netns/*,
|
||||
mount options=(rw, bind) /etc/netns/*/resolv.conf -> /etc/resolv.conf,
|
||||
mount fstype=sysfs -> /sys/,
|
||||
mount options=(rw, rshared) -> @{run}/netns/,
|
||||
mount options=(rw, rslave) -> /,
|
||||
|
||||
umount @{run}/netns/*,
|
||||
umount /sys/,
|
||||
|
|
|
@ -14,7 +14,7 @@ profile sync @{exec_path} {
|
|||
@{exec_path} mr,
|
||||
|
||||
# All paths where sync can be used to flush all write operations on a single file to disk
|
||||
/** rw,
|
||||
/{,**} rw,
|
||||
|
||||
include if exists <local/sync>
|
||||
}
|
||||
|
|
Loading…
Reference in a new issue