Skip to content

Commit d9150a3

Browse files
committed
policy/modules/services/incus: remove files_watch_all_dirs(incusd_t)
This is not reproducable anymore in current incus version Signed-off-by: Marc Schiffbauer <[email protected]>
1 parent cb4cc98 commit d9150a3

File tree

1 file changed

+0
-3
lines changed

1 file changed

+0
-3
lines changed

policy/modules/services/incus.te

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -118,9 +118,6 @@ kernel_mounton_kernel_sysctl_files(incusd_t)
118118
# read /etc/machine-id
119119
files_read_etc_runtime_files(incusd_t)
120120

121-
# watch /dev/hugepages
122-
files_watch_all_dirs(incusd_t)
123-
124121
# incus apparmor support wants to handle /sys/kernel/tracing
125122
fs_dontaudit_getattr_tracefs(incusd_t)
126123
fs_dontaudit_getattr_tracefs_dirs(incusd_t)

0 commit comments

Comments
 (0)