feat(profile): use the new @{tmp} variable.

It is only used with the owner statement.
This commit is contained in:
Alexandre Pujol 2024-05-02 22:12:02 +01:00
parent 0bbbe71422
commit 3f69b9fec4
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
257 changed files with 668 additions and 685 deletions

View file

@ -88,7 +88,7 @@ profile containerd @{exec_path} flags=(attach_disconnected) {
/tmp/cri-containerd.apparmor.d@{int} rwl,
/tmp/ctd-volume@{int}/{,**} rw,
owner /tmp/** rwkl,
owner @{tmp}/** rwkl,
owner /var/tmp/** rwkl,
@{sys}/fs/cgroup/kubepods/** r,

View file

@ -98,7 +98,7 @@ profile k3s @{exec_path} flags=(attach_disconnected) {
@{run}/xtables.lock rwk,
owner /var/tmp/** rwkl,
owner /tmp/** rwkl,
owner @{tmp}/** rwkl,
owner @{PROC}/@{pids}/cgroup r,
owner @{PROC}/@{pids}/cpuset r,