10000 fix: update aa-pg-profile for pljava · deerle/postgres@1f1bd2e · GitHub
[go: up one dir, main page]

Skip to content

Commit 1f1bd2e

Browse files
Lakshmipathidarora
authored andcommitted
fix: update aa-pg-profile for pljava
Signed-off-by: Lakshmipathi <lakshmi@supabase.io>
1 parent 53f1a53 commit 1f1bd2e

File tree

1 file changed

+7
-0
lines changed

1 file changed

+7
-0
lines changed

ebssurrogate/files/apparmor_profiles/usr.lib.postgresql.bin.postgres

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,8 +16,13 @@ deny @{HOME}/** rwx,
1616

1717
/data/pgdata/** r,
1818
/dev/shm rw,
19+
/etc/java-11-openjdk/logging.properties r,
20+
/etc/java-11-openjdk/security/default.policy r,
21+
/etc/java-11-openjdk/security/java.policy r,
22+
/etc/java-11-openjdk/security/java.security r,
1923
/etc/postgresql-custom/** r,
2024
/etc/postgresql/** r,
25+
/etc/timezone r,
2126
/etc/wal-g/config.json r,
2227
/run/systemd/notify rw,
2328
/usr/bin/cat rix,
@@ -27,12 +32,14 @@ deny @{HOME}/** rwx,
2732
/usr/local/bin/wal-g rix,
2833
/usr/local/lib/libSFCGAL.so.* mr,
2934
/usr/local/lib/libgroonga.so.* mr,
35+
/usr/local/pgsql/etc/pljava.policy r,
3036
/usr/share/postgresql/** r,
3137
/var/lib/postgresql/** rwl,
3238
/var/log/postgresql/** rw,
3339
/var/log/wal-g/** w,
3440
/var/run/systemd/notify rw,
3541
/{,var/}run/postgresql/** rw,
42+
owner /data/pgdata/ r,
3643
owner /data/pgdata/** rwl,
3744
owner /data/pgdata/pgroonga.log k,
3845
owner /dev/shm/ rw,

0 commit comments

Comments
 (0)
0