apparmor/apparmor-lessopen-nfs-workaround.diff
Christian Boltz f6659d8de7 Accepting request 663645 from home:cboltz
- add apparmor-lessopen-nfs-workaround.diff: allow network access in
  lessopen.sh for reading files on NFS (workaround for boo#1119937 /
  lp#1784499)

OBS-URL: https://build.opensuse.org/request/show/663645
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=229
2019-01-08 12:18:00 +00:00

16 lines
606 B
Diff

Index: profiles/apparmor.d/usr.bin.lessopen.sh
===================================================================
--- profiles/apparmor.d/usr.bin.lessopen.sh.orig 2019-01-06 20:05:38.582356924 +0100
+++ profiles/apparmor.d/usr.bin.lessopen.sh 2019-01-06 20:08:26.885706133 +0100
@@ -10,6 +10,10 @@
capability dac_override,
capability dac_read_search,
+ # workaround for https://bugzilla.opensuse.org/show_bug.cgi?id=1119937 / https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1784499
+ network inet stream,
+ network inet6 stream,
+
/** rk,
/bin/bash mrix,
/{usr/,}bin/rpm mrix,