fix(profile): snap: simplify cgroup access.
This commit is contained in:
parent
cd890bb81b
commit
5e38394986
1 changed files with 3 additions and 4 deletions
|
|
@ -157,12 +157,11 @@ profile snapd @{exec_path} {
|
|||
@{run}/systemd/private rw,
|
||||
|
||||
@{sys}/fs/cgroup/{,*/} r,
|
||||
@{sys}/fs/cgroup/cgroup.controllers r,
|
||||
@{sys}/fs/cgroup/system.slice/{,**/} r,
|
||||
@{sys}/fs/cgroup/system.slice/snap*.service/cgroup.procs r,
|
||||
@{sys}/fs/cgroup/*.slice/ r,
|
||||
@{sys}/fs/cgroup/*.slice/*.service/{,**/} r,
|
||||
@{sys}/fs/cgroup/*.slice/*-@{uid}.slice/*@@{uid}.service/app.slice/snap*.service/cgroup.procs r,
|
||||
@{sys}/fs/cgroup/*.slice/*.slice/{,**/} r,
|
||||
@{sys}/fs/cgroup/*.slice/**/cgroup.procs r,
|
||||
@{sys}/fs/cgroup/cgroup.controllers r,
|
||||
@{sys}/kernel/kexec_loaded r,
|
||||
@{sys}/kernel/security/apparmor/.notify r,
|
||||
@{sys}/kernel/security/apparmor/features/{,**} r,
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue