]> git.ipfire.org Git - thirdparty/libvirt.git/commitdiff
Allow unmounting some things libvirt mounted
authorDanny Sauer <gitlab@dannysauer.com>
Mon, 8 Jul 2024 04:30:25 +0000 (04:30 +0000)
committerAndrea Bolognani <abologna@redhat.com>
Wed, 7 Aug 2024 11:02:53 +0000 (13:02 +0200)
Signed-off-by: Danny Sauer <github@dannysauer.com>
Reviewed-by: Andrea Bolognani <abologna@redhat.com>
src/security/apparmor/usr.sbin.libvirtd.in
src/security/apparmor/usr.sbin.virtqemud.in

index 1601d73d479d89776be8e88279851a715d216dbd..47292d6c64bf782ea0a18bc49c079255362c03e6 100644 (file)
@@ -42,6 +42,7 @@ profile libvirtd @sbindir@/libvirtd flags=(attach_disconnected) {
   mount options=(rw, move) /dev/** -> /{,var/}run/libvirt/qemu/*{,/},
   mount options=(rw, move) /{,var/}run/libvirt/qemu/*.dev/ -> /dev/,
   mount options=(rw, move) /{,var/}run/libvirt/qemu/*{,/} -> /dev/**,
+  umount /{,var/}run/libvirt/qemu/*{,/},
 
   network inet stream,
   network inet dgram,
index 6b9c5d32d924075ae03f263fe970a8fef795bca0..bbc65131464a3a5f38dafa97115265a52c55b727 100644 (file)
@@ -42,6 +42,7 @@ profile virtqemud @sbindir@/virtqemud flags=(attach_disconnected) {
   mount options=(rw, move) /dev/** -> /{,var/}run/libvirt/qemu/*{,/},
   mount options=(rw, move) /{,var/}run/libvirt/qemu/*.dev/ -> /dev/,
   mount options=(rw, move) /{,var/}run/libvirt/qemu/*{,/} -> /dev/**,
+  umount /{,var/}run/libvirt/qemu/*{,/},
 
   network inet stream,
   network inet dgram,