[apparmor] [patch] allow inet6 in ping profile
apparmor at cboltz.de
Wed May 18 18:21:28 UTC 2016
the latest iputils merged ping and ping6 into a single binary that does
both IPv4 and IPv6 pings (by default, it really does both).
This means we need to allow network inet6 raw in the ping profile.
(contains more details and example output)
I propose this patch for trunk, 2.10 and 2.9 - even if it's unlikely
that someone using 2.9.x upgrades to the latest iputils ;-)
[ ping-inet6.diff ]
=== modified file 'profiles/apparmor.d/bin.ping'
--- profiles/apparmor.d/bin.ping 2015-10-20 21:12:35 +0000
+++ profiles/apparmor.d/bin.ping 2016-05-18 18:12:04 +0000
@@ -18,6 +18,7 @@
network inet raw,
+ network inet6 raw,
> When there isn't sufficient virtual memory, the compiler bails out,
> giving an internal error message. When I kill some processes, the
> error goes away.
And what is the compiler supposed to do instead? Go shopping for you
and buy more memory? [Falk Hueffner, on the GNU C++ compiler]
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 819 bytes
Desc: This is a digitally signed message part.
More information about the AppArmor