Unverified Commit c035b6f3 authored by Grimmauld's avatar Grimmauld Committed by GitHub
Browse files

nixos/miniflux: add apparmor paths for new go runtime (#444413)

parents 7a18cdab 2bda2d98
Loading
Loading
Loading
Loading
+7 −0
Original line number Diff line number Diff line
@@ -431,6 +431,13 @@ in
    "abstractions/python" = ''
      include "${pkgs.apparmor-profiles}/etc/apparmor.d/abstractions/python"
    '';
    "abstractions/golang" = ''
      # Container-aware GOMAXPROCS
      owner @{PROC}/@{pid}/mountinfo r,
      owner @{PROC}/@{pid}/cgroup r,
      @{sys}/fs/cgroup/**/{cpu.cfs_quota_us,cpu.cfs_period_us} r, # V1
      @{sys}/fs/cgroup/**/cpu.max r, # V2
    '';
    "abstractions/qt5" = ''
      include "${pkgs.apparmor-profiles}/etc/apparmor.d/abstractions/qt5"
    ''
+1 −1
Original line number Diff line number Diff line
@@ -212,9 +212,9 @@ in
        include <abstractions/base>
        include <abstractions/nameservice>
        include <abstractions/ssl_certs>
        include <abstractions/golang>
        include "${pkgs.apparmorRulesFromClosure { name = "miniflux"; } cfg.package}"
        r ${cfg.package}/bin/miniflux,
        r @{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size,
        rw /run/miniflux/**,
      }
    '';