From 19039eae0b22855278d730b5e12dbe13fa5b65d5 Mon Sep 17 00:00:00 2001 From: Bjorn Neergaard Date: Mon, 18 Sep 2023 16:41:03 -0600 Subject: [PATCH] profiles/apparmor: deny /sys/devices/virtual/powercap While this is not strictly necessary as the default OCI config masks this path, it is possible that the user disabled path masking, passed their own list, or is using a forked (or future) daemon version that has a modified default config/allows changing the default config. Add some defense-in-depth by also masking out this problematic hardware device with the AppArmor LSM. Signed-off-by: Bjorn Neergaard (cherry picked from commit bddd826d7ab083c7815ae23b6857a8c5856e4540) Signed-off-by: Bjorn Neergaard --- profiles/apparmor/template.go | 1 + 1 file changed, 1 insertion(+) diff --git a/profiles/apparmor/template.go b/profiles/apparmor/template.go index 5dcf35bf45..9f207e2014 100644 --- a/profiles/apparmor/template.go +++ b/profiles/apparmor/template.go @@ -47,6 +47,7 @@ profile {{.Name}} flags=(attach_disconnected,mediate_deleted) { deny /sys/fs/c[^g]*/** wklx, deny /sys/fs/cg[^r]*/** wklx, deny /sys/firmware/** rwklx, + deny /sys/devices/virtual/powercap/** rwklx, deny /sys/kernel/security/** rwklx, # suppress ptrace denials when using 'docker ps' or using 'ps' inside a container