Skip to content

Commit

Permalink
Add /opt to allowed directories
Browse files Browse the repository at this point in the history
Some applications like nginx from Bitnami is using /opt for
entrypoint and cmd bash scripts. We would like add this directory
to allowed paths.

Signed-off-by: Michal Jura <mjura@suse.com>
  • Loading branch information
mjura committed Dec 22, 2021
1 parent 6504f91 commit 82cb5be
Show file tree
Hide file tree
Showing 2 changed files with 5 additions and 0 deletions.
2 changes: 2 additions & 0 deletions contrib/etc/lockc/lockc.toml
Original file line number Diff line number Diff line change
Expand Up @@ -358,6 +358,7 @@ allowed_paths_access_restricted = [
"/home",
"/lib",
"/lib64",
"/opt",
"/pause",
"/proc",
"/run",
Expand Down Expand Up @@ -390,6 +391,7 @@ allowed_paths_access_baseline = [
"/home",
"/lib",
"/lib64",
"/opt",
"/pause",
"/proc",
"/run",
Expand Down
3 changes: 3 additions & 0 deletions lockc/src/settings.rs
Original file line number Diff line number Diff line change
Expand Up @@ -212,6 +212,7 @@ static DIR_ETC: &str = "/etc";
static DIR_LIB: &str = "/lib";
static DIR_LIB64: &str = "/lib64";
static PAUSE: &str = "/pause";
static DIR_OPT: &str = "/opt";
static DIR_PROC: &str = "/proc";
static DIR_RUN: &str = "/run";
static DIR_CGROUP: &str = "/sys/fs/cgroup";
Expand Down Expand Up @@ -460,6 +461,7 @@ impl Settings {
DIR_LIB.to_string(),
DIR_LIB64.to_string(),
PAUSE.to_string(),
DIR_OPT.to_string(),
DIR_PROC.to_string(),
DIR_RUN.to_string(),
DIR_CGROUP.to_string(),
Expand Down Expand Up @@ -494,6 +496,7 @@ impl Settings {
DIR_LIB.to_string(),
DIR_LIB64.to_string(),
PAUSE.to_string(),
DIR_OPT.to_string(),
DIR_PROC.to_string(),
DIR_RUN.to_string(),
DIR_CGROUP.to_string(),
Expand Down

0 comments on commit 82cb5be

Please # to comment.