AppArmor技术问题:如何让可执行文件调用另一可执行文件?
解决AppArmor中允许进程调用其他可执行文件的问题
嘿,我来帮你搞定这个问题!你现在的AppArmor配置只允许/my/executable在当前profile下执行,但它调用的/the/other/executable还没被授权,所以得调整配置文件,分两种常见场景来处理:
1. 让子进程继承当前profile运行
如果希望/the/other/executable受同一个myprof规则限制,直接在profile里添加它的执行权限就行,用ix标记(表示继承当前profile执行):
profile myprof { /my/executable ix, /the/other/executable ix, }
这样修改后,/my/executable就能调用/the/other/executable,而且子进程的权限完全遵循myprof的规则。如果子进程还需要其他操作(比如写文件、读配置),记得在myprof里补充对应的权限条目。
2. 让子进程切换到独立的AppArmor profile运行
如果/the/other/executable有自己的AppArmor profile(比如已经定义了theotherprof),更安全的做法是让子进程切换到那个profile运行,这时候用px标记:
profile myprof { /my/executable ix, /the/other/executable px, }
这种方式下,/the/other/executable会按照它自己的profile规则运行,不会继承myprof的权限,能实现更精细的权限隔离。当然前提是你已经为/the/other/executable创建并加载了对应的profile。
最后提醒下,修改完配置文件后,记得用apparmor_parser -r /path/to/your/myprof.conf重新加载规则,这样新配置才会生效哦!
内容的提问来源于stack exchange,提问作者Germán Diago
相关产品推荐
相关产品推荐

