mirror of
https://git.proxmox.com/git/mirror_lxc
synced 2025-08-03 08:52:48 +00:00
drop useless apparmor denies
mem and kmem are really in /dev, so this does us no good. Signed-off-by: Tycho Andersen <tycho@tycho.ws>
This commit is contained in:
parent
a00b86ac4a
commit
408dd86c76
@ -72,8 +72,6 @@
|
||||
|
||||
# block some other dangerous paths
|
||||
deny @{PROC}/kcore rwklx,
|
||||
deny @{PROC}/kmem rwklx,
|
||||
deny @{PROC}/mem rwklx,
|
||||
deny @{PROC}/sysrq-trigger rwklx,
|
||||
|
||||
# deny writes in /sys except for /sys/fs/cgroup, also allow
|
||||
|
@ -72,8 +72,6 @@
|
||||
|
||||
# block some other dangerous paths
|
||||
deny @{PROC}/kcore rwklx,
|
||||
deny @{PROC}/kmem rwklx,
|
||||
deny @{PROC}/mem rwklx,
|
||||
deny @{PROC}/sysrq-trigger rwklx,
|
||||
|
||||
# deny writes in /sys except for /sys/fs/cgroup, also allow
|
||||
|
@ -105,7 +105,7 @@ char *files_to_allow[] = { "/sys/class/net/lo/ifalias",
|
||||
"/proc/sys/kernel/shmmax",
|
||||
NULL };
|
||||
|
||||
char *files_to_deny[] = { "/proc/mem", "/proc/kmem",
|
||||
char *files_to_deny[] = {
|
||||
"/sys/kernel/uevent_helper",
|
||||
"/proc/sys/fs/file-nr",
|
||||
"/sys/kernel/mm/ksm/pages_to_scan",
|
||||
|
Loading…
Reference in New Issue
Block a user