diff --git a/profiles/apparmor/template.go b/profiles/apparmor/template.go index cf8c34ce8a..8dbc1b6102 100644 --- a/profiles/apparmor/template.go +++ b/profiles/apparmor/template.go @@ -25,6 +25,10 @@ profile {{.Name}} flags=(attach_disconnected,mediate_deleted) { umount, # Host (privileged) processes may send signals to container processes. signal (receive) peer=unconfined, + # runc may send signals to container processes (for "docker stop"). + signal (receive) peer=runc, + # crun may send signals to container processes (for "docker stop" when used with crun OCI runtime). + signal (receive) peer=crun, # dockerd may send signals to container processes (for "docker kill"). signal (receive) peer={{.DaemonProfile}}, # Container processes may send signals amongst themselves.