Unverified Commit 5fa7a6cb by Fred Smith Committed by GitHub

Merge pull request #4681 from edx/derf/xserver_sandbox_apparmor

xserver sandbox apparmor
parents 3fed8dd3 daa711d3
......@@ -57,8 +57,8 @@
- name: Load python-sandbox apparmor profile
template:
src: "usr.bin.python-sandbox.j2"
dest: "/etc/apparmor.d/edx_apparmor_sandbox"
src: "xserver-sandbox.j2"
dest: "/etc/apparmor.d/xserver-sandbox"
- include: deploy.yml
tags:
......
#include <tunables/global>
/usr/bin/python-sandbox {
{{ xserver_venv_sandbox_dir }}/bin/python {
#include <abstractions/base>
/usr/bin/python-sandbox mr,
{{ xserver_venv_sandbox_dir }}/bin/python mr,
{{ xserver_venv_sandbox_dir }}/** r,
{{ xserver_code_dir }}/sandbox/** r,
/tmp/grader-* wrix,
/usr/include/python2.7/** r,
/usr/local/lib/python2.7/** r,
/usr/lib/python2.7** rix,
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment