Files
snapd/tests/main
Maciej Borzecki a37f10c9a1 cmd/libsnap-confine-private: do not deny all devices when reusing the device cgroup
* cmd/libsnap-confine-private: do not deny all devices when reusing the device cgroup

With device cgroup v1, when reusing the cgroup (i.e. opening with
SC_DEVICE_CGROUP_FROM_EXISTING flag), we should not deny all devices, as this
will negatively affect the processes that are in the group.

This code path was executed by snap-device-helper, so it is possible that when
processing of real events from device changes the group could have become
broken.

Signed-off-by: Maciej Borzecki <maciej.zenon.borzecki@canonical.com>

* cmd/libsnap-confine-private/device-cgroup-support.c: add comment

Co-authored-by: Ian Johnson <person.uwsome@gmail.com>

* tests/main/security-device-cgroups-strict-enforced: verify that udev changes do not break device group settings

Signed-off-by: Maciej Borzecki <maciej.zenon.borzecki@canonical.com>

* tests/main/security-device-cgroups-strict-enforced: skip triggering events on 14.04

Signed-off-by: Maciej Borzecki <maciej.zenon.borzecki@canonical.com>

Co-authored-by: Alberto Mardegan <mardy@users.sourceforge.net>
Co-authored-by: Ian Johnson <person.uwsome@gmail.com>
2021-11-15 15:57:24 +01:00
..
2021-08-23 18:18:01 -03:00
2021-06-09 18:03:24 -03:00
2021-04-20 09:21:11 -03:00
2021-05-17 19:11:12 -03:00
2021-04-13 07:13:20 -03:00
2021-09-16 19:01:39 +01:00
2021-09-02 08:17:09 -03:00
2021-04-09 13:42:23 -03:00
2021-05-17 19:11:12 -03:00
2021-05-26 14:29:24 -03:00
2021-07-23 15:44:43 -03:00
2021-04-21 09:08:50 -03:00
2021-03-10 08:41:31 -03:00
2021-04-21 09:08:50 -03:00
2021-04-21 09:08:50 -03:00
2021-06-09 18:03:24 -03:00
2021-03-04 09:27:19 -03:00
2021-04-21 09:08:50 -03:00
2021-10-21 07:27:53 -05:00
2021-09-20 10:24:04 -03:00
2021-06-02 23:52:29 -03:00
2021-04-21 09:08:50 -03:00
2021-04-08 15:05:29 -03:00