diff --git a/contrib/apparmor/template.go b/contrib/apparmor/template.go index 5869cffaa..3ba0645a0 100644 --- a/contrib/apparmor/template.go +++ b/contrib/apparmor/template.go @@ -53,6 +53,10 @@ profile {{.Name}} flags=(attach_disconnected,mediate_deleted) { umount, # Host (privileged) processes may send signals to container processes. signal (receive) peer=unconfined, + # runc may send signals to container processes. + signal (receive) peer=runc, + # crun may send signals to container processes. + signal (receive) peer=crun, # Manager may send signals to container processes. signal (receive) peer={{.DaemonProfile}}, # Container processes may send signals amongst themselves.