Now:
- we don't open the PID file in main() anymore
- PID file and AF_UNIX socket are opened by pidfile_open() and
tap_sock_unix_open()
- write_pidfile() becomes pidfile_write()
Reported-by: Richard W.M. Jones
Signed-off-by: Stefano Brivio
---
contrib/apparmor/abstractions/pasta | 2 +-
contrib/apparmor/usr.bin.passt | 9 ++++++---
contrib/apparmor/usr.bin.pasta | 9 ++++++---
3 files changed, 13 insertions(+), 7 deletions(-)
diff --git a/contrib/apparmor/abstractions/pasta b/contrib/apparmor/abstractions/pasta
index 581ad1b..9f73bee 100644
--- a/contrib/apparmor/abstractions/pasta
+++ b/contrib/apparmor/abstractions/pasta
@@ -27,7 +27,7 @@
@{PROC}/@{pid}/net/udp r,
@{PROC}/@{pid}/net/udp6 r,
- @{run}/user/@{uid}/** rw, # pasta_open_ns(), main()
+ @{run}/user/@{uid}/** rw, # pasta_open_ns()
@{PROC}/[0-9]*/ns/ r, # pasta_netns_quit_init(),
@{PROC}/[0-9]*/ns/net r, # pasta_wait_for_ns(),
diff --git a/contrib/apparmor/usr.bin.passt b/contrib/apparmor/usr.bin.passt
index 564f82f..9568189 100644
--- a/contrib/apparmor/usr.bin.passt
+++ b/contrib/apparmor/usr.bin.passt
@@ -19,9 +19,12 @@ profile passt /usr/bin/passt{,.avx2} {
include
# Alternatively: include
- owner /tmp/** w, # tap_sock_unix_init(), pcap(),
- # write_pidfile(),
+ owner /tmp/** w, # tap_sock_unix_open(),
+ # tap_sock_unix_init(), pcap(),
+ # pidfile_open(),
+ # pidfile_write(),
# logfile_init()
- owner @{HOME}/** w, # pcap(), write_pidfile()
+ owner @{HOME}/** w, # pcap(), pidfile_open(),
+ # pidfile_write()
}
diff --git a/contrib/apparmor/usr.bin.pasta b/contrib/apparmor/usr.bin.pasta
index bdfeb71..2483968 100644
--- a/contrib/apparmor/usr.bin.pasta
+++ b/contrib/apparmor/usr.bin.pasta
@@ -19,10 +19,13 @@ profile pasta /usr/bin/pasta{,.avx2} flags=(attach_disconnected) {
include
# Alternatively: include
- /tmp/** rw, # tap_sock_unix_init(), pcap(),
- # write_pidfile(),
+ /tmp/** rw, # tap_sock_unix_open(),
+ # tap_sock_unix_init(), pcap(),
+ # pidfile_open(),
+ # pidfile_write(),
# logfile_init(),
# pasta_open_ns()
- owner @{HOME}/** w, # pcap(), write_pidfile()
+ owner @{HOME}/** w, # pcap(), pidfile_open(),
+ # pidfile_write()
}
--
2.43.0