feat(profile): use the new @{tmp} variable.
It is only used with the owner statement.
This commit is contained in:
parent
0bbbe71422
commit
3f69b9fec4
257 changed files with 668 additions and 685 deletions
|
|
@ -88,7 +88,7 @@ profile containerd @{exec_path} flags=(attach_disconnected) {
|
|||
|
||||
/tmp/cri-containerd.apparmor.d@{int} rwl,
|
||||
/tmp/ctd-volume@{int}/{,**} rw,
|
||||
owner /tmp/** rwkl,
|
||||
owner @{tmp}/** rwkl,
|
||||
owner /var/tmp/** rwkl,
|
||||
|
||||
@{sys}/fs/cgroup/kubepods/** r,
|
||||
|
|
|
|||
|
|
@ -98,7 +98,7 @@ profile k3s @{exec_path} flags=(attach_disconnected) {
|
|||
@{run}/xtables.lock rwk,
|
||||
|
||||
owner /var/tmp/** rwkl,
|
||||
owner /tmp/** rwkl,
|
||||
owner @{tmp}/** rwkl,
|
||||
|
||||
owner @{PROC}/@{pids}/cgroup r,
|
||||
owner @{PROC}/@{pids}/cpuset r,
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue