From 9881b02bd92be0236f0f09ad27c1b7f1dccaead8 Mon Sep 17 00:00:00 2001 From: daemon1024 Date: Thu, 5 Dec 2024 16:22:55 +0530 Subject: [PATCH] fix(apparmor): add dbus to baseline apparmor host/privileged profile Signed-off-by: daemon1024 --- KubeArmor/enforcer/appArmorEnforcer.go | 1 + KubeArmor/enforcer/appArmorTemplate.go | 1 + 2 files changed, 2 insertions(+) diff --git a/KubeArmor/enforcer/appArmorEnforcer.go b/KubeArmor/enforcer/appArmorEnforcer.go index 711eff0ee8..a1857c6ef1 100644 --- a/KubeArmor/enforcer/appArmorEnforcer.go +++ b/KubeArmor/enforcer/appArmorEnforcer.go @@ -374,6 +374,7 @@ umount, signal, unix, ptrace, +dbus, file, network, diff --git a/KubeArmor/enforcer/appArmorTemplate.go b/KubeArmor/enforcer/appArmorTemplate.go index a4411e9bc8..0913d5e39d 100644 --- a/KubeArmor/enforcer/appArmorTemplate.go +++ b/KubeArmor/enforcer/appArmorTemplate.go @@ -213,6 +213,7 @@ profile {{$v := $.Name | split "."}}{{$v._0}}_{{ regexReplaceAllLiteral "[^a-z A signal, unix, ptrace, + dbus, {{end}} {{ if .File}}file,{{end}} {{ if .Network}}network,{{end}}