From: Cole Robinson Date: Wed, 9 Oct 2019 18:21:24 +0000 (-0400) Subject: security: apparmor: Allow RO /usr/share/edk2/ X-Git-Tag: v5.9.0-rc1~312 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=4dfc4d525e630382cbdb98a53280a64b81782be3;p=thirdparty%2Flibvirt.git security: apparmor: Allow RO /usr/share/edk2/ On Fedora, already whitelisted paths to AAVMF and OVMF binaries are symlinks to binaries under /usr/share/edk2/. Add that directory to the RO whitelist so virt-aa-helper-test passes Reviewed-by: Michal Privoznik Signed-off-by: Cole Robinson --- diff --git a/src/security/virt-aa-helper.c b/src/security/virt-aa-helper.c index d9f6b5638b..509187ac36 100644 --- a/src/security/virt-aa-helper.c +++ b/src/security/virt-aa-helper.c @@ -505,6 +505,7 @@ valid_path(const char *path, const bool readonly) "/vmlinuz", "/initrd", "/initrd.img", + "/usr/share/edk2/", "/usr/share/OVMF/", /* for OVMF images */ "/usr/share/ovmf/", /* for OVMF images */ "/usr/share/AAVMF/", /* for AAVMF images */