mirror of
https://github.com/moby/moby.git
synced 2022-11-09 12:21:53 -05:00
Merge pull request #39992 from thaJeztah/apparmor_fix_network_paths
AppArmor: add missing rules for running in userns
This commit is contained in:
commit
d1e837d2a8
1 changed files with 3 additions and 0 deletions
|
@ -31,6 +31,9 @@ profile /usr/bin/docker (attach_disconnected, complain) {
|
||||||
@{DOCKER_GRAPH_PATH}/** rwl,
|
@{DOCKER_GRAPH_PATH}/** rwl,
|
||||||
@{DOCKER_GRAPH_PATH}/network/files/boltdb.db k,
|
@{DOCKER_GRAPH_PATH}/network/files/boltdb.db k,
|
||||||
@{DOCKER_GRAPH_PATH}/network/files/local-kv.db k,
|
@{DOCKER_GRAPH_PATH}/network/files/local-kv.db k,
|
||||||
|
# For user namespaces:
|
||||||
|
@{DOCKER_GRAPH_PATH}/[0-9]*.[0-9]*/network/files/boltdb.db k,
|
||||||
|
@{DOCKER_GRAPH_PATH}/[0-9]*.[0-9]*/network/files/local-kv.db k,
|
||||||
|
|
||||||
# For non-root client use:
|
# For non-root client use:
|
||||||
/dev/urandom r,
|
/dev/urandom r,
|
||||||
|
|
Loading…
Reference in a new issue