Configuring apparmor / seccomp for a snap to allow sendmsg and mkfifo?
Jamie Strandboge
jamie at canonical.com
Tue Oct 25 15:05:22 UTC 2016
On Tue, 2016-10-25 at 07:53 -0700, Dan Kegel wrote:
> On Tue, Oct 25, 2016 at 6:33 AM, Jamie Strandboge <jamie at canonical.com> wrote:
> >
> > It is planned to allow snaps via
> > seccomp arg filtering policy the ability to create S_IFIFO and S_IFREG files
> > (ie, pipes and regular files, but not character and block devices), but it
> > hasn't landed yet.
> Is this it? https://bugs.launchpad.net/ubuntu/+source/ubuntu-core-launcher/+b
> ug/1446748
>
That is the bug tracking the feature to implement seccomp arg filtering, yes. I
just filed a bug for using that feature to allow mknod with pipes here:
https://bugs.launchpad.net/snappy/+bug/1636540
--
Jamie Strandboge | http://www.canonical.com
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: This is a digitally signed message part
URL: <https://lists.ubuntu.com/archives/snapcraft/attachments/20161025/964fd31d/attachment.sig>
More information about the Snapcraft
mailing list