From: Tycho Andersen Date: Tue, 3 Oct 2017 05:00:21 +0000 (-0600) Subject: drop useless apparmor denies X-Git-Tag: lxc-1.0.11~2 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=38f7ef1b61c5f43b817fd2537cf2d5803deebc35;p=thirdparty%2Flxc.git drop useless apparmor denies mem and kmem are really in /dev, so this does us no good. Signed-off-by: Tycho Andersen --- diff --git a/config/apparmor/abstractions/container-base b/config/apparmor/abstractions/container-base index 70aa45b1f..94cc7d590 100644 --- a/config/apparmor/abstractions/container-base +++ b/config/apparmor/abstractions/container-base @@ -76,8 +76,6 @@ # block some other dangerous paths deny @{PROC}/kcore rwklx, - deny @{PROC}/kmem rwklx, - deny @{PROC}/mem rwklx, deny @{PROC}/sysrq-trigger rwklx, # deny writes in /sys except for /sys/fs/cgroup, also allow diff --git a/config/apparmor/abstractions/container-base.in b/config/apparmor/abstractions/container-base.in index 09deeb511..37960c401 100644 --- a/config/apparmor/abstractions/container-base.in +++ b/config/apparmor/abstractions/container-base.in @@ -76,8 +76,6 @@ # block some other dangerous paths deny @{PROC}/kcore rwklx, - deny @{PROC}/kmem rwklx, - deny @{PROC}/mem rwklx, deny @{PROC}/sysrq-trigger rwklx, # deny writes in /sys except for /sys/fs/cgroup, also allow diff --git a/src/tests/aa.c b/src/tests/aa.c index 1ab199723..f21b2b70e 100644 --- a/src/tests/aa.c +++ b/src/tests/aa.c @@ -105,7 +105,7 @@ char *files_to_allow[] = { "/sys/class/net/lo/ifalias", "/proc/sys/kernel/shmmax", NULL }; -char *files_to_deny[] = { "/proc/mem", "/proc/kmem", +char *files_to_deny[] = { "/sys/kernel/uevent_helper", "/proc/sys/fs/file-nr", "/sys/kernel/mm/ksm/pages_to_scan",