Advertisement
pyron83

askubuntu_snapd

Apr 17th, 2024
703
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Bash 0.92 KB | Software | 0 0
  1. ~$ diff  /etc/apparmor.d/usr.lib.snapd.snap-confine.real usr.lib.snapd.snap-confine.real.OJM
  2. 157,166d156
  3. <     # For mounting base dir by dir (write dirs and mount on them)
  4. <     /tmp/snap.rootfs_** rw,
  5. <     mount options=(remount ro) -> /tmp/snap.rootfs_*/,
  6. <     mount options=(rw rbind) /snap/*/*/**/ -> /tmp/snap.rootfs_**/,
  7. <     # For mounting individual files
  8. <     mount options=(rw bind) /snap/*/*/** -> /tmp/snap.rootfs_*/**,
  9. <     mount options=(rw rslave) -> /tmp/snap.rootfs_**/,
  10. <     # Allow mounting dirs from /
  11. <     mount options=(rw rbind) /*/ -> /tmp/snap.rootfs_**/,
  12. <
  13. 175d164
  14. <     mount fstype=tmpfs none -> /tmp/snap.rootfs_*/,
  15. 296,297c285
  16. <     # For dir on dir mounts, we do need write permissions in /var though
  17. <     audit deny /tmp/snap.rootfs_*/{var/lib/,var/lib/snapd/,var/lib/snapd/hostfs/} w,
  18. ---
  19. >     audit deny /tmp/snap.rootfs_*/{var/,var/lib/,var/lib/snapd/,var/lib/snapd/hostfs/} w,
  20.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement