Add apparmor rule to support /usr/sbin

It seems that as of Disco *1 /sbin is a symlink to /usr/sbin. This
patch adds support for file in either location.

*1 https://lists.ubuntu.com/archives/ubuntu-devel-announce/2018-November/001253.html

Change-Id: I66fa27f3f5e29d83cfea0f1afb33374303ab4669
Closes-Bug: #1925511
This commit is contained in:
Liam Young 2021-04-26 13:51:06 +00:00
parent bfc3436a32
commit 120235f359

View File

@ -74,20 +74,20 @@
/run/lock/nova/nova-iptables wk, /run/lock/nova/nova-iptables wk,
/run/lock/qemu-nbd-nbd* w, /run/lock/qemu-nbd-nbd* w,
/run/openvswitch/db.sock rw, /run/openvswitch/db.sock rw,
/sbin/blockdev rix, /{usr/,}sbin/blockdev rix,
/sbin/brctl rix, /{usr/,}sbin/brctl rix,
/sbin/iscsiadm rix, /{usr/,}sbin/iscsiadm rix,
/sbin/ldconfig rix, /{usr/,}sbin/ldconfig rix,
/sbin/ldconfig.real rix, /{usr/,}sbin/ldconfig.real rix,
/sbin/mkfs rix, /{usr/,}sbin/mkfs rix,
/sbin/mkfs.fat rix, /{usr/,}sbin/mkfs.fat rix,
/sbin/hdparm rix, /{usr/,}sbin/hdparm rix,
/sbin/xtables-multi rix, /{usr/,}sbin/xtables-multi rix,
/sbin/mkswap rix, /{usr/,}sbin/mkswap rix,
/sbin/multipath rix, /{usr/,}sbin/multipath rix,
/sbin/multipathd rix, /{usr/,}sbin/multipathd rix,
/sbin/e2label rix, /{usr/,}sbin/e2label rix,
/sbin/tune2fs rix, /{usr/,}sbin/tune2fs rix,
/sys/block/ r, /sys/block/ r,
/sys/class/fc_host/{,**} r, /sys/class/fc_host/{,**} r,
/sys/class/iscsi_host/ r, /sys/class/iscsi_host/ r,