From mboxrd@z Thu Jan 1 00:00:00 1970 Received: by passt.top (Postfix, from userid 1000) id 5B27E5A0272; Wed, 3 Apr 2024 21:04:25 +0200 (CEST) From: Stefano Brivio To: passt-dev@passt.top Subject: [PATCH 2/3] apparmor: Expand scope of @{run}/user access, allow writing PID files too Date: Wed, 3 Apr 2024 21:04:20 +0200 Message-ID: <20240403190425.2848764-3-sbrivio@redhat.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20240403190425.2848764-1-sbrivio@redhat.com> References: <20240403190425.2848764-1-sbrivio@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Message-ID-Hash: JOZMYCSY756WI43RSO6Q7FXONV5JG2DC X-Message-ID-Hash: JOZMYCSY756WI43RSO6Q7FXONV5JG2DC X-MailFrom: sbrivio@passt.top X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: =?UTF-8?q?J=C3=B6rg=20Sonnenberger?= , Danish Prakash , Christian Boltz , Paul Holzinger X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: V2l0aCBQb2RtYW4ncyBjdXN0b20gbmV0d29ya3MsIHBhc3RhIHdpbGwgdHlwaWNhbGx5IG5lZWQg dG8gb3BlbiB0aGUNCnRhcmdldCBuZXR3b3JrIG5hbWVzcGFjZSBhdCAvcnVuL3VzZXIvPFVJRD4v Y29udGFpbmVycy9uZXR3b3JrczoNCmdyYW50IGFjY2VzcyB0byBhbnl0aGluZyB1bmRlciAvcnVu L3VzZXIvPFVJRD4gaW5zdGVhZCBvZiBsaW1pdGluZyBpdA0KdG8gc29tZSBzdWJwYXRoLg0KDQpO b3RlIHRoYXQgaW4gdGhpcyBjYXNlLCBQb2RtYW4gd2lsbCBuZWVkIHBhc3RhIHRvIHdyaXRlIG91 dCBhIFBJRA0KZmlsZSwgc28gd2UgbmVlZCB3cml0ZSBhY2Nlc3MsIGZvciBzaW1pbGFyIGxvY2F0 aW9ucywgdG9vLg0KDQpSZXBvcnRlZC1ieTogSsO2cmcgU29ubmVuYmVyZ2VyIDxqb2VyZ0BiZWMu ZGU+DQpMaW5rOiBodHRwczovL2dpdGh1Yi5jb20vY29udGFpbmVycy9idWlsZGFoL2lzc3Vlcy81 NDQwDQpMaW5rOiBodHRwczovL2J1Z3ppbGxhLnN1c2UuY29tL3Nob3dfYnVnLmNnaT9pZD0xMjIx ODQwDQpTaWduZWQtb2ZmLWJ5OiBTdGVmYW5vIEJyaXZpbyA8c2JyaXZpb0ByZWRoYXQuY29tPg0K LS0tDQogY29udHJpYi9hcHBhcm1vci9hYnN0cmFjdGlvbnMvcGFzdGEgfCAyICstDQogMSBmaWxl IGNoYW5nZWQsIDEgaW5zZXJ0aW9uKCspLCAxIGRlbGV0aW9uKC0pDQoNCmRpZmYgLS1naXQgYS9j b250cmliL2FwcGFybW9yL2Fic3RyYWN0aW9ucy9wYXN0YSBiL2NvbnRyaWIvYXBwYXJtb3IvYWJz dHJhY3Rpb25zL3Bhc3RhDQppbmRleCBhODkwMzkxLi4wNjBjYWFiIDEwMDY0NA0KLS0tIGEvY29u dHJpYi9hcHBhcm1vci9hYnN0cmFjdGlvbnMvcGFzdGENCisrKyBiL2NvbnRyaWIvYXBwYXJtb3Iv YWJzdHJhY3Rpb25zL3Bhc3RhDQpAQCAtMjcsNyArMjcsNyBAQA0KICAgQHtQUk9DfS9Ae3BpZH0v bmV0L3VkcAkJciwNCiAgIEB7UFJPQ30vQHtwaWR9L25ldC91ZHA2CQlyLA0KIA0KLSAgQHtydW59 L3VzZXIvQHt1aWR9L25ldG5zLyoJCXIsCSMgcGFzdGFfb3Blbl9ucygpLCBwYXN0YS5jDQorICBA e3J1bn0vdXNlci9Ae3VpZH0vKioJCQlydywJIyBwYXN0YV9vcGVuX25zKCksIG1haW4oKQ0KIA0K ICAgQHtQUk9DfS9bMC05XSovbnMvbmV0CQkJciwJIyBwYXN0YV93YWl0X2Zvcl9ucygpLA0KICAg QHtQUk9DfS9bMC05XSovbnMvdXNlcgkJciwJIyBjb25mX3Bhc3RhX25zKCkNCi0tIA0KMi40My4w DQoNCg==