Skip to content

Commit b818d62

Browse files
committed
[apparmor] support symlinked /snap
Just hardcoding /var/lib/snapd since this goes away with strict anyway.
1 parent 6c01a84 commit b818d62

File tree

4 files changed

+4
-4
lines changed

4 files changed

+4
-4
lines changed

src/platform/backends/qemu/dnsmasq_process_spec.cpp

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -91,7 +91,7 @@ profile %1 flags=(attach_disconnected) {
9191
%3/{usr/,}lib/@{multiarch}/{,**/}*.so* rm,
9292
9393
# CLASSIC ONLY: need to specify required libs from core snap
94-
/snap/core18/*/{,usr/}lib/@{multiarch}/{,**/}*.so* rm,
94+
{,/var/lib/snapd}/snap/core18/*/{,usr/}lib/@{multiarch}/{,**/}*.so* rm,
9595
9696
%5/dnsmasq.leases rw, # Leases file
9797
%5/dnsmasq.hosts r, # Hosts file

src/platform/backends/qemu/qemu_vm_process_spec.cpp

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -234,7 +234,7 @@ profile %1 flags=(attach_disconnected) {
234234
%4/{,usr/}lib/{,@{multiarch}/}{,**/}*.so* rm,
235235
236236
# CLASSIC ONLY: need to specify required libs from core snap
237-
/snap/core18/*/{,usr/}lib/@{multiarch}/{,**/}*.so* rm,
237+
{,/var/lib/snapd}/snap/core18/*/{,usr/}lib/@{multiarch}/{,**/}*.so* rm,
238238
239239
# Disk images
240240
%6 rwk, # QCow2 filesystem image

src/platform/backends/shared/linux/qemuimg_process_spec.cpp

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,7 @@ profile %1 flags=(attach_disconnected) {
5050
%3/{usr/,}lib/@{multiarch}/{,**/}*.so* rm,
5151
5252
# CLASSIC ONLY: need to specify required libs from core snap
53-
/snap/core18/*/{,usr/}lib/@{multiarch}/{,**/}*.so* rm,
53+
{,/var/lib/snapd}/snap/core18/*/{,usr/}lib/@{multiarch}/{,**/}*.so* rm,
5454
5555
# Subdirectory containing disk image(s)
5656
%5/** rwk,

src/platform/backends/shared/sshfs_server_process_spec.cpp

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -110,7 +110,7 @@ profile %1 flags=(attach_disconnected) {
110110
%3/{usr/,}lib/** rm,
111111
112112
# CLASSIC ONLY: need to specify required libs from core snap
113-
/snap/core18/*/{,usr/}lib/@{multiarch}/{,**/}*.so* rm,
113+
{,/var/lib/snapd}/core18/*/{,usr/}lib/@{multiarch}/{,**/}*.so* rm,
114114
115115
# allow full access just to this user-specified source directory on the host
116116
%4/ rw,

0 commit comments

Comments
 (0)