apparmor/profiles
Georgia Garcia 789cda2f08 add special unprivileged_userns profile
Unprivileged user namespace creation is allowed an will result in a
transition into the unprivileged_userns profile. The
unprivileged_userns profile with then deny all capabilities within the
profile. Execution of applications is allowed within the
unprivileged_userns profile but, they will result in a stack with the
unprivileged_userns profile, that is to say the unprivileged_userns
profile can not be dropped (capabilities can not be gained).

If the unprivileged_userns profile does not exist, unprivileged user
namespace creation is denied as before.

Signed-off-by: Georgia Garcia <georgia.garcia@canonical.com>
2024-02-02 10:52:26 -03:00
..
apparmor/profiles/extras firefox: remove owner restrictions for /proc/$pid/net/* 2023-12-24 17:19:10 +01:00
apparmor.d add special unprivileged_userns profile 2024-02-02 10:52:26 -03:00
Makefile Don't create local/* profile sniplets by default 2023-08-20 11:49:10 +02:00