Re: [libvirt] [PATCH v2 3/5] apparmor: allow expected /tmp access patterns

2018-08-15 Thread Jamie Strandboge
On Tue, 2018-08-14 at 08:18 +0200, Christian Ehrhardt wrote: > Several cases were found needing /tmp, for example ceph will try to > list /tmp > This is a compromise of security and usability: > - we only allow generally enumerating the base dir > - enumerating anything deeper in the dir is at

[libvirt] [PATCH v2 3/5] apparmor: allow expected /tmp access patterns

2018-08-14 Thread Christian Ehrhardt
Several cases were found needing /tmp, for example ceph will try to list /tmp This is a compromise of security and usability: - we only allow generally enumerating the base dir - enumerating anything deeper in the dir is at least guarded by the "owner" restriction, but while that protects