Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Apparmor profile for FRR daemons #17900

Open
jslarraz opened this issue Jan 22, 2025 · 0 comments
Open

Apparmor profile for FRR daemons #17900

jslarraz opened this issue Jan 22, 2025 · 0 comments

Comments

@jslarraz
Copy link

Hi folks,

I started to work on an apparmor profile for the daemons included in the FRR suite. The apparmor upstream made a couple of suggestions while reviewing those profiles. The path used to store crash logs could possibly be a source of troubles, considering that frr is hardcoded and the pid guessable (and in worst case, the number of possible pids is not that big). They recommended to use a mktemp-generated name or move to a directory that is not world-writable.

I would also very much appreciate if someone could take a look to the apparmor profiles and/or test them trying to identify any potentially missing directory.

Thanks,
Jorge

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant