Merge pull request #10123 from woky/apparmor-runc
apparmor: Allow confined runc to kill containers
This commit is contained in:
commit
01ed3ff123
@ -55,6 +55,10 @@ profile {{.Name}} flags=(attach_disconnected,mediate_deleted) {
|
|||||||
umount,
|
umount,
|
||||||
# Host (privileged) processes may send signals to container processes.
|
# Host (privileged) processes may send signals to container processes.
|
||||||
signal (receive) peer=unconfined,
|
signal (receive) peer=unconfined,
|
||||||
|
# runc may send signals to container processes.
|
||||||
|
signal (receive) peer=runc,
|
||||||
|
# crun may send signals to container processes.
|
||||||
|
signal (receive) peer=crun,
|
||||||
# Manager may send signals to container processes.
|
# Manager may send signals to container processes.
|
||||||
signal (receive) peer={{.DaemonProfile}},
|
signal (receive) peer={{.DaemonProfile}},
|
||||||
# Container processes may send signals amongst themselves.
|
# Container processes may send signals amongst themselves.
|
||||||
|
Loading…
Reference in New Issue
Block a user