]> git.ipfire.org Git - thirdparty/lxc.git/commit
apparmor: Block access to /proc/kcore
authorStéphane Graber <stgraber@ubuntu.com>
Sun, 28 Dec 2014 17:33:29 +0000 (18:33 +0100)
committerStéphane Graber <stgraber@ubuntu.com>
Mon, 5 Jan 2015 21:28:33 +0000 (16:28 -0500)
commit98b745498bf97637f68311f944903777f3ee1e67
tree891cf2e3bd6a19c9fa93caf425d9c6680ba8c91d
parentabf117c398c957b213feebe3fa6dea3107c3a452
apparmor: Block access to /proc/kcore

Just like we block access to mem and kmem, there's no good reason for
the container to have access to kcore.

Reported-by: Marc Schaefer
Signed-off-by: Stéphane Graber <stgraber@ubuntu.com>
Acked-by: Serge E. Hallyn <serge.hallyn@ubuntu.com>
config/apparmor/abstractions/container-base
config/apparmor/abstractions/container-base.in