Configuring apparmor / seccomp for a snap to allow sendmsg and mkfifo?

Jamie Strandboge jamie at canonical.com
Tue Oct 25 15:05:22 UTC 2016


On Tue, 2016-10-25 at 07:53 -0700, Dan Kegel wrote:
> On Tue, Oct 25, 2016 at 6:33 AM, Jamie Strandboge <jamie at canonical.com> wrote:
>> > It is planned to allow snaps via
> > seccomp arg filtering policy the ability to create S_IFIFO and S_IFREG files
> > (ie, pipes and regular files, but not character and block devices), but it
> > hasn't landed yet.
> Is this it?  https://bugs.launchpad.net/ubuntu/+source/ubuntu-core-launcher/+b
> ug/1446748
> 
That is the bug tracking the feature to implement seccomp arg filtering, yes. I
just filed a bug for using that feature to allow mknod with pipes here:

https://bugs.launchpad.net/snappy/+bug/1636540


-- 
Jamie Strandboge             | http://www.canonical.com

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: This is a digitally signed message part
URL: <https://lists.ubuntu.com/archives/snapcraft/attachments/20161025/964fd31d/attachment.sig>


More information about the Snapcraft mailing list