feat(profiles): add initial userns rule.

Require apparmor 4 to be enabled.
This commit is contained in:
Alexandre Pujol 2023-11-19 11:19:24 +00:00
parent 6dc990ac02
commit 88555a12d0
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC
5 changed files with 11 additions and 5 deletions

View file

@ -22,11 +22,9 @@ var (
regAttachments = regexp.MustCompile(`(profile .* @{exec_path})`)
regFlags = regexp.MustCompile(`flags=\(([^)]+)\)`)
regProfileHeader = regexp.MustCompile(` {`)
regAbi4To3 = util.ToRegexRepl([]string{
`abi/4.0`, `abi/3.0`,
`(?m)^.*mqueue.*$`, ``,
`(?m)^.*userns.*$`, ``,
`(?m)^.*io_uring.*$`, ``,
regAbi4To3 = util.ToRegexRepl([]string{ // Currently Abi3 -> Abi4
`abi/3.0`, `abi/4.0`,
`# userns,`, `userns,`,
})
)