mirror of
https://gitlab.com/apparmor/apparmor.git
synced 2025-03-04 00:14:44 +01:00
profiles: add unconfined foliate profile
Foliate is using user namespaces via bwrap. For now add an unconfined profile to support it. Fixes: https://github.com/johnfactotum/foliate/issues/1271 Signed-off-by: John Johansen <john.johansen@canonical.com>
This commit is contained in:
parent
41d4664124
commit
36d0ceaf19
1 changed files with 12 additions and 0 deletions
12
profiles/apparmor.d/foliate
Normal file
12
profiles/apparmor.d/foliate
Normal file
|
@ -0,0 +1,12 @@
|
|||
# This profile allows everything and only exists to give the
|
||||
# application a name instead of having the label "unconfined"
|
||||
|
||||
abi <abi/4.0>,
|
||||
include <tunables/global>
|
||||
|
||||
profile foliate /usr/bin/foliate flags=(unconfined) {
|
||||
userns,
|
||||
|
||||
# Site-specific additions and overrides. See local/README for details.
|
||||
include if exists <local/foliate>
|
||||
}
|
Loading…
Add table
Reference in a new issue