]> glassweightruler.freedombox.rocks Git - waydroid.git/commitdiff
AppArmor policy setup has been moved to the Makefile
authorАзалия Смарагдова <charming.flurry@yandex.ru>
Sat, 12 Nov 2022 19:07:46 +0000 (00:07 +0500)
committerAlessandro Astone <ales.astone@gmail.com>
Fri, 18 Nov 2022 14:19:17 +0000 (15:19 +0100)
Makefile
data/configs/config_1
data/configs/config_2
tools/helpers/lxc.py

index 810902e0555faa3281850de99fce7531eaa04ff5..4652ea525b11debe2de90e2947adc21e0073b3c7 100644 (file)
--- a/Makefile
+++ b/Makefile
@@ -31,3 +31,14 @@ install:
        if [ $(USE_NFTABLES) = 1 ]; then \
                sed '/LXC_USE_NFT=/ s/false/true/' -i $(INSTALL_WAYDROID_DIR)/data/scripts/waydroid-net.sh; \
        fi
+
+apparmor:
+       cp -f data/configs/adbd /etc/apparmor.d/adbd
+       apparmor_parser -r /etc/apparmor.d/adbd
+       cp -f data/configs/android_app /etc/apparmor.d/android_app
+       apparmor_parser -r /etc/apparmor.d/android_app
+       cp -f data/configs/lxc-waydroid /etc/apparmor.d/lxc/lxc-waydroid
+       apparmor_parser -r /etc/apparmor.d/lxc/lxc-waydroid
+       sed --sandbox -i "s/lxc.aa_profile = unconfined/lxc.aa_profile = lxc-waydroid/g;" /var/lib/waydroid/lxc/waydroid/config
+       sed --sandbox -i "s/lxc.apparmor.profile = unconfined/lxc.apparmor.profile = lxc-waydroid/g;" /var/lib/waydroid/lxc/waydroid/config
+
index 52f1261a7d6df5911a28cf2d4c668baf2bc6e458..365cac307b34b88c046f93a5afbdfbd2ceb1440c 100644 (file)
@@ -2,7 +2,7 @@ lxc.utsname = waydroid
 
 lxc.init_cmd = /init
 
-lxc.aa_profile = lxc-waydroid
+lxc.aa_profile = unconfined
 lxc.seccomp = /var/lib/waydroid/lxc/waydroid/waydroid.seccomp
 
 lxc.network.type = veth
index 2d5498aaeebfcf07bfcd81f5653ed1852f46a800..dcc6fc4de25b6cb784a4283d9ba7999cdb423652 100644 (file)
@@ -1,6 +1,6 @@
 lxc.uts.name = waydroid
 
-lxc.apparmor.profile = lxc-waydroid
+lxc.apparmor.profile = unconfined
 lxc.seccomp.profile = /var/lib/waydroid/lxc/waydroid/waydroid.seccomp
 
 lxc.no_new_privs = 1
index d77493600b06409142e3ef052f70e6c652a4ad5e..45d5e5d0947136bf1f2b2baefb0de2a9b2284b53 100644 (file)
@@ -135,8 +135,6 @@ def set_lxc_config(args):
         raise OSError("LXC is not installed")
     config_paths = tools.config.tools_src + "/data/configs/config_"
     seccomp_profile = tools.config.tools_src + "/data/configs/waydroid.seccomp"
-    apparmor_profiles = [tools.config.tools_src + "/data/configs/" + "lxc-waydroid",tools.config.tools_src + "/data/configs/" + "android_app",tools.config.tools_src + "/data/configs/" + "adbd"]
-    apparmor_profile_dir = "/etc/apparmor.d/"
 
     config_snippets = [ config_paths + "base" ]
     # lxc v1 is a bit special because some options got renamed later
@@ -157,22 +155,6 @@ def set_lxc_config(args):
     command = ["cp", "-fpr", seccomp_profile, lxc_path + "/waydroid.seccomp"]
     tools.helpers.run.user(args, command)
 
-    try:
-        command = ["cp", "-i", apparmor_profiles[0], apparmor_profile_dir + "lxc/lxc-waydroid"]
-        tools.helpers.run.user(args, command)
-        command = ["apparmor_parser", "-r", apparmor_profile_dir + "lxc/lxc-waydroid"]
-        tools.helpers.run.user(args, command)
-        command = ["cp", "-i", apparmor_profiles[1], apparmor_profile_dir + "android_app"]
-        tools.helpers.run.user(args, command)
-        command = ["apparmor_parser", "-r", apparmor_profile_dir + "android_app"]
-        tools.helpers.run.user(args, command)
-        command = ["cp", "-i", apparmor_profiles[2], apparmor_profile_dir + "adbd"]
-        tools.helpers.run.user(args, command)
-        command = ["apparmor_parser", "-r", apparmor_profile_dir + "adbd"]
-        tools.helpers.run.user(args, command)
-    except:
-        logging.warning("An error has occurred while installing AppArmor profiles. If profiles are not installed, or AppArmor is disabled or not supported on your system, then the container will run without AppArmor protection.")
-
     nodes = generate_nodes_lxc_config(args)
     config_nodes_tmp_path = args.work + "/config_nodes"
     config_nodes = open(config_nodes_tmp_path, "w")