You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AppArmor技术问题:如何让可执行文件调用另一可执行文件?

解决AppArmor中允许进程调用其他可执行文件的问题

嘿,我来帮你搞定这个问题!你现在的AppArmor配置只允许/my/executable在当前profile下执行,但它调用的/the/other/executable还没被授权,所以得调整配置文件,分两种常见场景来处理:

1. 让子进程继承当前profile运行

如果希望/the/other/executable受同一个myprof规则限制,直接在profile里添加它的执行权限就行,用ix标记(表示继承当前profile执行):

profile myprof {
    /my/executable ix,
    /the/other/executable ix,
}

这样修改后,/my/executable就能调用/the/other/executable,而且子进程的权限完全遵循myprof的规则。如果子进程还需要其他操作(比如写文件、读配置),记得在myprof里补充对应的权限条目。

2. 让子进程切换到独立的AppArmor profile运行

如果/the/other/executable有自己的AppArmor profile(比如已经定义了theotherprof),更安全的做法是让子进程切换到那个profile运行,这时候用px标记:

profile myprof {
    /my/executable ix,
    /the/other/executable px,
}

这种方式下,/the/other/executable会按照它自己的profile规则运行,不会继承myprof的权限,能实现更精细的权限隔离。当然前提是你已经为/the/other/executable创建并加载了对应的profile。

最后提醒下,修改完配置文件后,记得用apparmor_parser -r /path/to/your/myprof.conf重新加载规则,这样新配置才会生效哦!

内容的提问来源于stack exchange,提问作者Germán Diago

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 06:38:28