Skip to content

Commit 01ed3ff

Browse files
authored
Merge pull request containerd#10123 from woky/apparmor-runc
apparmor: Allow confined runc to kill containers
2 parents c4c3c6e + 094bafe commit 01ed3ff

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

contrib/apparmor/template.go

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -55,6 +55,10 @@ profile {{.Name}} flags=(attach_disconnected,mediate_deleted) {
5555
umount,
5656
# Host (privileged) processes may send signals to container processes.
5757
signal (receive) peer=unconfined,
58+
# runc may send signals to container processes.
59+
signal (receive) peer=runc,
60+
# crun may send signals to container processes.
61+
signal (receive) peer=crun,
5862
# Manager may send signals to container processes.
5963
signal (receive) peer={{.DaemonProfile}},
6064
# Container processes may send signals amongst themselves.

0 commit comments

Comments
 (0)