Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
contrib/apparmor: deny /sys/devices/virtual/powercap
While this is not strictly necessary as the default OCI config masks this path, it is possible that the user disabled path masking, passed their own list, or is using a forked (or future) daemon version that has a modified default config/allows changing the default config. Add some defense-in-depth by also masking out this problematic hardware device with the AppArmor LSM. Signed-off-by: Bjorn Neergaard <[email protected]> (cherry picked from commit 6c6dfcb) Signed-off-by: Bjorn Neergaard <[email protected]>
- Loading branch information