ca2749e1bd
In practical terms, passt doesn't benefit from the additional protection offered by the AGPL over the GPL, because it's not suitable to be executed over a computer network. Further, restricting the distribution under the version 3 of the GPL wouldn't provide any practical advantage either, as long as the passt codebase is concerned, and might cause unnecessary compatibility dilemmas. Change licensing terms to the GNU General Public License Version 2, or any later version, with written permission from all current and past contributors, namely: myself, David Gibson, Laine Stump, Andrea Bolognani, Paul Holzinger, Richard W.M. Jones, Chris Kuhn, Florian Weimer, Giuseppe Scrivano, Stefan Hajnoczi, and Vasiliy Ulyanov. Signed-off-by: Stefano Brivio <sbrivio@redhat.com>
47 lines
1.1 KiB
Text
47 lines
1.1 KiB
Text
# SPDX-License-Identifier: GPL-2.0-or-later
|
|
#
|
|
# PASST - Plug A Simple Socket Transport
|
|
# for qemu/UNIX domain socket mode
|
|
#
|
|
# PASTA - Pack A Subtle Tap Abstraction
|
|
# for network namespace/tap device mode
|
|
#
|
|
# contrib/apparmor/abstractions/passt - Abstraction for passt(1)
|
|
#
|
|
# Copyright (c) 2022 Red Hat GmbH
|
|
# Author: Stefano Brivio <sbrivio@redhat.com>
|
|
|
|
abi <abi/3.0>,
|
|
|
|
include <abstractions/base>
|
|
|
|
# Alternatively: include <abstractions/nameservice>
|
|
@{etc_ro}/resolv.conf r, # get_dns(), conf.c
|
|
|
|
capability net_bind_service, # isolation.c, conf.c
|
|
capability setuid,
|
|
capability setgid,
|
|
capability sys_admin,
|
|
capability setpcap,
|
|
capability net_admin,
|
|
capability sys_ptrace,
|
|
|
|
/ r, # isolate_prefork(), isolation.c
|
|
mount "" -> "/",
|
|
mount "" -> "/tmp/",
|
|
pivot_root "/tmp/" -> "/tmp/",
|
|
umount "/",
|
|
|
|
network netlink raw, # nl_sock_init_do(), netlink.c
|
|
|
|
network inet stream, # tcp.c
|
|
network inet6 stream,
|
|
|
|
network inet dgram, # udp.c
|
|
network inet6 dgram,
|
|
|
|
network unix stream, # tap.c
|
|
|
|
network unix dgram, # __openlog(), log.c
|
|
|
|
/usr/bin/passt.avx2 ix, # arch_avx2_exec(), arch.c
|