Skip to content

Commit af60804

Browse files
authored
Merge pull request from GHSA-jq35-85cj-fj4p
[24.0 backport] deny /sys/devices/virtual/powercap
2 parents 3cf363e + 19039ea commit af60804

2 files changed

Lines changed: 2 additions & 0 deletions

File tree

oci/defaults.go

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -113,6 +113,7 @@ func DefaultLinuxSpec() specs.Spec {
113113
"/proc/sched_debug",
114114
"/proc/scsi",
115115
"/sys/firmware",
116+
"/sys/devices/virtual/powercap",
116117
},
117118
ReadonlyPaths: []string{
118119
"/proc/bus",

profiles/apparmor/template.go

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,7 @@ profile {{.Name}} flags=(attach_disconnected,mediate_deleted) {
4747
deny /sys/fs/c[^g]*/** wklx,
4848
deny /sys/fs/cg[^r]*/** wklx,
4949
deny /sys/firmware/** rwklx,
50+
deny /sys/devices/virtual/powercap/** rwklx,
5051
deny /sys/kernel/security/** rwklx,
5152
5253
# suppress ptrace denials when using 'docker ps' or using 'ps' inside a container

0 commit comments

Comments
 (0)