[lxc-devel] [lxc/lxc] 773bd2: apparmor: allow writes to sem* and msg* sysctls

GitHub noreply at github.com
Tue Apr 29 21:45:27 UTC 2014


  Branch: refs/heads/master
  Home:   https://github.com/lxc/lxc
  Commit: 773bd28258371ad0058ff946c5cf94419920ffdd
      https://github.com/lxc/lxc/commit/773bd28258371ad0058ff946c5cf94419920ffdd
  Author: Serge Hallyn <serge.hallyn at ubuntu.com>
  Date:   2014-04-29 (Tue, 29 Apr 2014)

  Changed paths:
    M config/apparmor/abstractions/container-base
    M config/apparmor/container-rules
    M config/apparmor/container-rules.base

  Log Message:
  -----------
  apparmor: allow writes to sem* and msg* sysctls

/proc/sys/kernel/sem* and /proc/sys/kernel/msg* are ipc sysctls
which are properly namespaced.  Allow writes to them from
containers.

Reported-by: Dan Kegel <dank at kegel.com>
Signed-off-by: Serge Hallyn <serge.hallyn at ubuntu.com>
Acked-by: Stéphane Graber <stgraber at ubuntu.com>




More information about the lxc-devel mailing list