[systemd-devel] Can AppArmor be used with NoNewPrivileges=true enabled

Lennart Poettering lennart at poettering.net
Mon Aug 21 09:00:38 UTC 2023


On Fr, 18.08.23 13:25, 嵩智 (dirksu at gmail.com) wrote:

> Hi all,
>
> I had a program which launched by systemd, and had NoNewPrivileges=true in
> the service file. This program will use GIO subprocess to execute another
> program2. Program2 will failed to run if applied AppArmor profile to it.
> But if mark NoNewPrivileges=true out, then everything works fine. Can
> NoNewPrivileges=true can work with AppArmor together?

No AppArmor experts here. pleast contact the AppArmor community
instead. The concept that NoNewPrivileges= exposes is called
PR_SET_NO_NEW_PRIVS, hence ask about AA compat with that.

Lennart

--
Lennart Poettering, Berlin


More information about the systemd-devel mailing list