]>
Commit | Line | Data |
---|---|---|
198b363f SH |
1 | # Run lxc-generate-aa-rules.py on this file after any modification, to generate |
2 | # the container-rules file which is appended to container-base.in to create the | |
3 | # final abstractions/container-base. | |
4 | ||
5 | block /sys | |
6 | allow /sys/fs/cgroup/** | |
7 | allow /sys/devices/virtual/net/** | |
8 | allow /sys/class/net/** | |
94a77f3f | 9 | block /proc/sys |
198b363f | 10 | allow /proc/sys/kernel/shm* |
773bd282 SH |
11 | allow /proc/sys/kernel/sem* |
12 | allow /proc/sys/kernel/msg* | |
94a77f3f SH |
13 | allow /proc/sys/kernel/hostname |
14 | allow /proc/sys/kernel/domainname | |
15 | allow /proc/sys/net/** |