master

Christian Ehrhardt

apparmor: fix ptrace rules with kernel 4.18

Due to kernel upstream change 338d0be4 ("apparmor: fix ptrace read check")
libvirt now hits apparmor denies like:
apparmor="DENIED" operation="ptrace" profile=""
pid=4409 comm="libvirtd" requested_mask="read" denied_mask="read"

Extend the ptrace rule to also allow 'ptrace (read)' for libvirtd to work
with these newer kernels.

Fixes: https://bugs.launchpad.net/bugs/1788603

Reported-by: Thadeu Lima de Souza Cascardo <thadeu cascardo canonical com>
Reviewed-by: Erik Skultety <eskultet redhat com>
Acked-by: Jamie Strandboge <jamie canonical com>
Signed-off-by: Christian Ehrhardt <christian ehrhardt canonical com>

