diff --git a/files/apparmor/usr.bin.ceph-osd b/files/apparmor/usr.bin.ceph-osd index 95846077..960dad95 100644 --- a/files/apparmor/usr.bin.ceph-osd +++ b/files/apparmor/usr.bin.ceph-osd @@ -38,6 +38,7 @@ /dev/ r, /dev/** rwk, + /run/udev/data/* r, /sys/devices/** r, /run/blkid/blkid.tab r, @@ -48,4 +49,55 @@ /usr/share/distro-info/** r, /etc/lsb-release r, /etc/debian_version r, + + /usr/bin/sudo Px -> ceph-osd-sudo, +} + +profile ceph-osd-sudo flags=(attach_disconnected) { + #include + #include + #include + #include + + capability audit_write, + capability setgid, + capability setuid, + capability sys_resource, + + /usr/bin/sudo r, + /usr/libexec/sudo/* mr, + + /etc/default/locale r, + /etc/environment r, + /etc/security/limits.d/ r, + /etc/security/limits.d/* r, + /etc/sudo.conf r, + /etc/sudoers r, + /etc/sudoers.d/ r, + /etc/sudoers.d/* r, + + owner @{PROC}/1/limits r, + owner @{PROC}/@{pids}/stat r, + + /usr/sbin/nvme Cx, + /usr/sbin/smartctl Cx, + + profile /usr/sbin/nvme { + #include + + /usr/sbin/nvme r, + } + + profile /usr/sbin/smartctl { + #include + + capability sys_admin, + capability sys_rawio, + + /usr/sbin/smartctl r, + /var/lib/smartmontools/** r, + + /dev/* r, + /sys/devices/** r, + } }