nixos/apparmor: allow closure of selected mallocLib, fixes #125415

This commit is contained in:
Julien Moutinho 2021-06-06 17:30:45 +02:00
parent c43e0f4873
commit 22e52be3b3

View file

@ -91,7 +91,10 @@ in
"abstractions/base" = ''
r /etc/ld-nix.so.preload,
r ${config.environment.etc."ld-nix.so.preload".source},
mr ${providerLibPath},
include "${pkgs.apparmorRulesFromClosure {
name = "mallocLib";
baseRules = ["mr $path/lib/**.so*"];
} [ mallocLib ] }"
'';
};
};