[libvirt] [PATCH] AppArmor: allow QEMU to set_process_name.

Christian Ehrhardt christian.ehrhardt at canonical.com
Mon Dec 5 16:30:25 UTC 2016


On Mon, Dec 5, 2016 at 12:21 PM, intrigeri <intrigeri+libvirt at boum.org>
wrote:

> +  @{PROC}/@{pid}/task/@{tid}/comm rw,
>


Hi,
we have used the following for now that we planned to submit soon:
owner @{PROC}/@{pid}/task/[0-9]*/comm rw

But I like yours more since you are adding the explicit TID instead of a
pattern.
I'm convinced you confirmed your fix working, but I wonder if might want to
consider the "owner" part we had.

CCing a few people who were involved on the old patch.


-- 
Christian Ehrhardt
Software Engineer, Ubuntu Server
Canonical Ltd
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/libvir-list/attachments/20161205/1843731a/attachment-0001.htm>


More information about the libvir-list mailing list