Merge php-fpm: widen allowed socket paths

It is common for packaged PHP applications to ship a PHP-FPM
configuration using a scheme of "$app.sock" or or "$app.socket" instead
of using a generic FPM socket.

Signed-off-by: Georg Pfuetzenreuter <mail@georg-pfuetzenreuter.net>

MR: https://gitlab.com/apparmor/apparmor/-/merge_requests/1406
Approved-by: John Johansen <john@jjmx.net>
Merged-by: John Johansen <john@jjmx.net>
(cherry picked from commit bfa9147182)
Signed-off-by: John Johansen <john.johansen@canonical.com>
This commit is contained in:
John Johansen 2024-11-06 03:05:29 +00:00 committed by John Johansen
parent 450813869a
commit be8d85603e

View file

@ -34,7 +34,7 @@ profile php-fpm /usr/{bin,sbin}/php-fpm* flags=(attach_disconnected) {
# we need to be able to create all sockets
@{run}/php{,-fpm,-fpm-legacy}/php*-fpm.pid rw,
@{run}/php*-fpm.pid rw,
@{run}/php{,-fpm,-fpm-legacy}/php*-fpm.sock rwlk,
@{run}/php{,-fpm,-fpm-legacy}/*.sock{,et} rwlk,
# LP: #2061113
owner @{run}/systemd/notify w,