mirror of
https://gitlab.com/apparmor/apparmor.git
synced 2025-03-04 08:24:42 +01:00
abstractions/opencl-nvidia: don't allow PUx on nvidia-modprobe
This commit is contained in:
parent
ae771b475a
commit
8f9bd5b0e3
1 changed files with 7 additions and 1 deletions
|
@ -6,7 +6,13 @@
|
|||
|
||||
# Executables
|
||||
|
||||
/usr/bin/nvidia-modprobe PUx,
|
||||
# https://github.com/NVIDIA/nvidia-modprobe
|
||||
# This setuid executable is used to create various device files and load the
|
||||
# the nvidia kernel module and is therefore not appropriate for a general
|
||||
# purpose abstraction. Confined applications currently need to add this rule
|
||||
# in their policy. At some point, a profile may be provided for this command
|
||||
# such that Px would succeed.
|
||||
#/usr/bin/nvidia-modprobe Pix,
|
||||
|
||||
# System files
|
||||
|
||||
|
|
Loading…
Add table
Reference in a new issue