Re: [PATCH] apparmor: allow libvirt to send term signal to unconfined

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 02/06/2018 03:54 PM, Christian Ehrhardt wrote:
> On Thu, Jan 25, 2018 at 9:09 PM, Jamie Strandboge <jamie@xxxxxxxxxxxxx> wrote:
>> On Wed, 2018-01-24 at 10:41 +0100, intrigeri wrote:
>>> Hi,
>>>
>>>
>>> Guido Günther:
>>>> --- a/examples/apparmor/usr.sbin.libvirtd
>>>> +++ b/examples/apparmor/usr.sbin.libvirtd
>>>> @@ -63,7 +63,7 @@
>>>>    signal (send) peer=/usr/sbin/dnsmasq,
>>>>    signal (read, send) peer=libvirt-*,
>>>> -  signal (send) set=("kill") peer=unconfined,
>>>> +  signal (send) set=("kill", "term") peer=unconfined,
>>>
>> LGTM too. +1 to apply.
> 
> 2 x +1
> 1x resolved Discussion
> 
> IMHO nothing should block this from being committed - so ping?
> 
> +1 from me as well btw
> 

I've just pushed this. BTW: haven't DV granted commit access to somebody
just recently so that they can push these apparmor patches?

Michal

--
libvir-list mailing list
libvir-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/libvir-list




[Index of Archives]     [Virt Tools]     [Libvirt Users]     [Lib OS Info]     [Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite News]     [KDE Users]     [Fedora Tools]

  Powered by Linux