Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

crun doesn't use apparmor stacking if confined and nnp set #1385

Closed
idleroamer opened this issue Jan 15, 2024 · 0 comments · Fixed by #1409
Closed

crun doesn't use apparmor stacking if confined and nnp set #1385

idleroamer opened this issue Jan 15, 2024 · 0 comments · Fixed by #1409

Comments

@idleroamer
Copy link
Contributor

In case crun is confined under apparmor and no_new_privileges flag set for containers,
the only way apparmor allows a change of profile is when a profile is stacked on top of current profile to ensure no new permissions are gained

idleroamer added a commit to idleroamer/crun that referenced this issue Jan 15, 2024
In case crun is running under apparmor profile and
no_new_privileges flag set for containers
the only way apparmor allows a change of profile
is when a profile is stacked on top of current profile
to ensure no new permissions are gained

Closes: containers#1385
Signed-off-by: 😎Mostafa Emami <mustafaemami@gmail.com>
idleroamer added a commit to idleroamer/crun that referenced this issue Jan 15, 2024
In case crun is running under apparmor profile and
no_new_privileges flag set for containers
the only way apparmor allows a change of profile
is when a profile is stacked on top of current profile
to ensure no new permissions are gained

Closes: containers#1385
Signed-off-by: 😎Mostafa Emami <mustafaemami@gmail.com>
idleroamer added a commit to idleroamer/crun that referenced this issue Jan 15, 2024
In case crun is running under apparmor profile and
no_new_privileges flag set for containers
the only way apparmor allows a change of profile
is when a profile is stacked on top of current profile
to ensure no new permissions are gained

Closes: containers#1385
Signed-off-by: 😎Mostafa Emami <mustafaemami@gmail.com>
idleroamer added a commit to idleroamer/crun that referenced this issue Jan 15, 2024
In case crun is running under apparmor profile and
no_new_privileges flag set for containers
the only way apparmor allows a change of profile
is when a profile is stacked on top of current profile
to ensure no new permissions are gained

Closes: containers#1385
Signed-off-by: 😎Mostafa Emami <mustafaemami@gmail.com>
idleroamer added a commit to idleroamer/crun that referenced this issue Jan 16, 2024
In case crun is running under apparmor profile and
no_new_privileges flag set for containers
the only way apparmor allows a change of profile
is when a profile is stacked on top of current profile
to ensure no new permissions are gained

Closes: containers#1385
Signed-off-by: 😎Mostafa Emami <mustafaemami@gmail.com>
idleroamer added a commit to idleroamer/crun that referenced this issue Jan 16, 2024
In case crun is running under apparmor profile and
no_new_privileges flag set for containers
the only way apparmor allows a change of profile
is when a profile is stacked on top of current profile
to ensure no new permissions are gained

Closes: containers#1385
Signed-off-by: 😎Mostafa Emami <mustafaemami@gmail.com>
idleroamer added a commit to idleroamer/crun that referenced this issue Jan 16, 2024
In case crun is running under apparmor profile and
no_new_privileges flag set for containers
the only way apparmor allows a change of profile
is when a profile is stacked on top of current profile
to ensure no new permissions are gained

Closes: containers#1385
Signed-off-by: 😎Mostafa Emami <mustafaemami@gmail.com>
idleroamer added a commit to idleroamer/crun that referenced this issue Jan 16, 2024
In case crun is running under apparmor profile and
no_new_privileges flag set for containers
the only way apparmor allows a change of profile
is when a profile is stacked on top of current profile
to ensure no new permissions are gained

Closes: containers#1385
Signed-off-by: 😎Mostafa Emami <mustafaemami@gmail.com>
idleroamer added a commit to idleroamer/crun that referenced this issue Jan 16, 2024
In case crun is running under apparmor profile and
no_new_privileges flag set for containers
the only way apparmor allows a change of profile
is when a profile is stacked on top of current profile
to ensure no new permissions are gained

Closes: containers#1385
Signed-off-by: 😎Mostafa Emami <mustafaemami@gmail.com>
idleroamer added a commit to idleroamer/crun that referenced this issue Jan 16, 2024
In case crun is running under apparmor profile and
no_new_privileges flag set for containers
the only way apparmor allows a change of profile
is when a profile is stacked on top of current profile
to ensure no new permissions are gained

Closes: containers#1385
Signed-off-by: 😎Mostafa Emami <mustafaemami@gmail.com>
idleroamer added a commit to idleroamer/crun that referenced this issue Jan 16, 2024
In case crun is running under apparmor profile and
no_new_privileges flag set for containers
the only way apparmor allows a change of profile
is when a profile is stacked on top of current profile
to ensure no new permissions are gained

Closes: containers#1385
Signed-off-by: 😎Mostafa Emami <mustafaemami@gmail.com>
idleroamer added a commit to idleroamer/crun that referenced this issue Jan 17, 2024
In case crun is running under apparmor profile and
no_new_privileges flag set for containers
the only way apparmor allows a change of profile
is when a profile is stacked on top of current profile
to ensure no new permissions are gained

Closes: containers#1385
Signed-off-by: 😎Mostafa Emami <mustafaemami@gmail.com>
idleroamer added a commit to idleroamer/crun that referenced this issue Feb 1, 2024
Closes: containers#1385
Signed-off-by: 😎Mostafa Emami <mustafaemami@gmail.com>
idleroamer added a commit to idleroamer/crun that referenced this issue Feb 2, 2024
Closes: containers#1385
Signed-off-by: 😎Mostafa Emami <mustafaemami@gmail.com>
idleroamer added a commit to idleroamer/crun that referenced this issue Feb 2, 2024
Closes: containers#1385
Signed-off-by: 😎Mostafa Emami <mustafaemami@gmail.com>
idleroamer added a commit to idleroamer/crun that referenced this issue Feb 2, 2024
Closes: containers#1385
Signed-off-by: 😎Mostafa Emami <mustafaemami@gmail.com>
idleroamer added a commit to idleroamer/crun that referenced this issue Feb 2, 2024
Closes: containers#1385
Signed-off-by: 😎Mostafa Emami <mustafaemami@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant