Ubuntu Pastebin

Paste from zyga at Thu, 7 Jul 2016 18:55:39 +0000

Download as text
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
diff --git a/debian/usr.bin.snap-confine b/debian/usr.bin.snap-confine
index e8db4d7..4f243cd 100644
--- a/debian/usr.bin.snap-confine
+++ b/debian/usr.bin.snap-confine
@@ -119,6 +119,9 @@
     # Allow snaps to share content amongst themselves.
     mount options=(rw bind) /snap/*/** -> /snap/*/**,
     mount options=(ro bind) /snap/*/** -> /snap/*/**,
+    # But we don't want anyone to touch /snap/bin
+    deny audit mount /snap/bin/** -> /**,
+    deny audit mount /** -> /snap/bin/**,
 
     # nvidia handling, glob needs /usr/** and the launcher must be
     # able to bind mount the nvidia dir
Download as text