]> git.ipfire.org Git - thirdparty/lxc.git/commit
apparmor: Block access to /proc/kcore
authorStéphane Graber <stgraber@ubuntu.com>
Sun, 28 Dec 2014 17:33:29 +0000 (18:33 +0100)
committerStéphane Graber <stgraber@ubuntu.com>
Fri, 30 Jan 2015 08:51:19 +0000 (09:51 +0100)
commit1a18db0a6cd4b8a9db6245b2d59367a3f8c337c0
tree8ed1098189052a2fbf66d2952148cbd1eb9f8625
parentfca113ed229df759a831b65f6ea6d130ccd93030
apparmor: Block access to /proc/kcore

Just like we block access to mem and kmem, there's no good reason for
the container to have access to kcore.

Reported-by: Marc Schaefer
Signed-off-by: Stéphane Graber <stgraber@ubuntu.com>
Acked-by: Serge E. Hallyn <serge.hallyn@ubuntu.com>
config/apparmor/abstractions/container-base
config/apparmor/abstractions/container-base.in