From: Pierre-Elliott Bécue Date: Sat, 10 Aug 2019 20:07:42 +0000 (+0200) Subject: [aa-profile] Deny access to /proc/acpi/** X-Git-Tag: lxc-4.0.0~129^2 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=ec90f35b4cfdd9a22e518b7e7801c8fbd55b2f99;p=thirdparty%2Flxc.git [aa-profile] Deny access to /proc/acpi/** Signed-off-by: Pierre-Elliott Bécue --- diff --git a/config/apparmor/abstractions/container-base.in b/config/apparmor/abstractions/container-base.in index 1a3ead89a..2606fb64c 100644 --- a/config/apparmor/abstractions/container-base.in +++ b/config/apparmor/abstractions/container-base.in @@ -73,6 +73,7 @@ # block some other dangerous paths deny @{PROC}/kcore rwklx, deny @{PROC}/sysrq-trigger rwklx, + deny @{PROC}/acpi/** rwklx, # deny writes in /sys except for /sys/fs/cgroup, also allow # fusectl, securityfs and debugfs to be mounted there (read-only)