Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ++ sudo DEBIAN_FRONTEND=noninteractive http_proxy= https_proxy= no_proxy= apt-get --option Dpkg::Options::=--force-confold --assume-yes install apparmor-utils
- Reading package lists... Done
- Building dependency tree
- Reading state information... Done
- apparmor-utils is already the newest version.
- 0 upgraded, 0 newly installed, 0 to remove and 84 not upgraded.
- ++ sudo aa-complain /etc/apparmor.d/usr.sbin.libvirtd
- Traceback (most recent call last):
- File "/usr/lib/python3/dist-packages/apparmor/aa.py", line 2910, in parse_profile_data
- re.compile(p_re)
- File "/usr/lib/python3.4/re.py", line 219, in compile
- return _compile(pattern, flags)
- File "/usr/lib/python3.4/re.py", line 288, in _compile
- p = sre_compile.compile(pattern, flags)
- File "/usr/lib/python3.4/sre_compile.py", line 465, in compile
- p = sre_parse.parse(p, flags)
- File "/usr/lib/python3.4/sre_parse.py", line 751, in parse
- raise error("unbalanced parenthesis")
- sre_constants.error: unbalanced parenthesis
- During handling of the above exception, another exception occurred:
- Traceback (most recent call last):
- File "/usr/sbin/aa-complain", line 30, in <module>
- tool.cmd_complain()
- File "/usr/lib/python3/dist-packages/apparmor/tools.py", line 154, in cmd_complain
- apparmor.read_profiles()
- File "/usr/lib/python3/dist-packages/apparmor/aa.py", line 2594, in read_profiles
- read_profile(profile_dir + '/' + file, True)
- File "/usr/lib/python3/dist-packages/apparmor/aa.py", line 2620, in read_profile
- profile_data = parse_profile_data(data, file, 0)
- File "/usr/lib/python3/dist-packages/apparmor/aa.py", line 2912, in parse_profile_data
- raise AppArmorException(_('Syntax Error: Invalid Regex %(path)s in file: %(file)s line: %(line)s') % { 'path': path, 'file': file, 'line': lineno + 1 })
- apparmor.common.AppArmorException: 'Syntax Error: Invalid Regex @{PROC}/{*,**^[0-9*],sys/kernel/shm*} in file: /etc/apparmor.d/docker line: 16'
- gal@gal-ThinkPad-X230:/opt/stack$ more /etc/apparmor.d/docker
- #include <tunables/global>
- profile docker-default flags=(attach_disconnected,mediate_deleted) {
- #include <abstractions/base>
- network,
- capability,
- file,
- umount,
- # deny @{PROC}/{*,**^[0-9*],sys/kernel/shm*} wkx,
- deny @{PROC}/sysrq-trigger rwklx,
- deny @{PROC}/mem rwklx,
- deny @{PROC}/kmem rwklx,
- deny @{PROC}/kcore rwklx,
- deny mount,
- deny /sys/[^f]*/** wklx,
- deny /sys/f[^s]*/** wklx,
- deny /sys/fs/[^c]*/** wklx,
- deny /sys/fs/c[^g]*/** wklx,
- deny /sys/fs/cg[^r]*/** wklx,
- deny /sys/firmware/efi/efivars/** rwklx,
- deny /sys/kernel/security/** rwklx,
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement