[systemd-devel] Can AppArmor be used with NoNewPrivileges=true enabled
Lennart Poettering
lennart at poettering.net
Mon Aug 21 09:00:38 UTC 2023
On Fr, 18.08.23 13:25, 嵩智 (dirksu at gmail.com) wrote:
> Hi all,
>
> I had a program which launched by systemd, and had NoNewPrivileges=true in
> the service file. This program will use GIO subprocess to execute another
> program2. Program2 will failed to run if applied AppArmor profile to it.
> But if mark NoNewPrivileges=true out, then everything works fine. Can
> NoNewPrivileges=true can work with AppArmor together?
No AppArmor experts here. pleast contact the AppArmor community
instead. The concept that NoNewPrivileges= exposes is called
PR_SET_NO_NEW_PRIVS, hence ask about AA compat with that.
Lennart
--
Lennart Poettering, Berlin
More information about the systemd-devel
mailing list