Skip to content
This repository was archived by the owner on Oct 13, 2023. It is now read-only.

Commit b9b1b0b

Browse files
committed
AppArmor: add missing rules for running in userns
Signed-off-by: Sebastiaan van Stijn <github@gone.nl> (cherry picked from commit 404d87ec6946aaa9c130b64c0c75514a2fcd50c0) Signed-off-by: Sebastiaan van Stijn <github@gone.nl> Upstream-commit: 08420b1c958e80df9fc10c2b92e21bf88b144142 Component: engine
1 parent 20666c2 commit b9b1b0b

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

components/engine/contrib/apparmor/template.go

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,9 @@ profile /usr/bin/docker (attach_disconnected, complain) {
3131
@{DOCKER_GRAPH_PATH}/** rwl,
3232
@{DOCKER_GRAPH_PATH}/network/files/boltdb.db k,
3333
@{DOCKER_GRAPH_PATH}/network/files/local-kv.db k,
34+
# For user namespaces:
35+
@{DOCKER_GRAPH_PATH}/[0-9]*.[0-9]*/network/files/boltdb.db k,
36+
@{DOCKER_GRAPH_PATH}/[0-9]*.[0-9]*/network/files/local-kv.db k,
3437
3538
# For non-root client use:
3639
/dev/urandom r,

0 commit comments

Comments
 (0)