]> git.ipfire.org Git - thirdparty/libvirt.git/commitdiff
virt-aa-helper: Actually fix AppArmor profile
authorAndrea Bolognani <abologna@redhat.com>
Tue, 20 Aug 2019 07:54:12 +0000 (09:54 +0200)
committerAndrea Bolognani <abologna@redhat.com>
Tue, 20 Aug 2019 08:35:18 +0000 (10:35 +0200)
Tried previously in

  commit b1eb8b3e8fd1d4cb1da8e5e2b16f2c10837fd823
  Author: Andrea Bolognani <abologna@redhat.com>
  Date:   Mon Aug 19 10:23:42 2019 +0200

    virt-aa-helper: Fix AppArmor profile

  v5.6.0-243-gb1eb8b3e8f

with somewhat disappointing results.

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
src/security/apparmor/usr.lib.libvirt.virt-aa-helper

index d81dddef30ebb8710b02ceb0409fbf30a0a7084e..64772f075696996f681066f1ec36c7ff906c0978 100644 (file)
@@ -18,8 +18,8 @@ profile virt-aa-helper /usr/{lib,lib64}/libvirt/virt-aa-helper {
   @{PROC}/filesystems r,
 
   # Used when internally running another command (namely apparmor_parser)
-  @{PROC}/self/fd r,
-  @{PROC}/@{pid}/fd r,
+  @{PROC}/self/fd/ r,
+  @{PROC}/@{pid}/fd/ r,
 
   /etc/libnl-3/classid r,