From af1ade69e7287827180e0f45c0f4c2724a63a47d Mon Sep 17 00:00:00 2001 From: Slawek Kaplonski Date: Thu, 19 Nov 2020 13:37:30 +0100 Subject: [PATCH] Remove "find" rule from rootwrap filters It isn't used anymore by Neutron. Change-Id: I6f28077e1df8ab65cca834044e47383f38bbb443 --- etc/neutron/rootwrap.d/l3.filters | 1 - etc/neutron/rootwrap.d/linuxbridge-plugin.filters | 1 - etc/neutron/rootwrap.d/openvswitch-plugin.filters | 1 - 3 files changed, 3 deletions(-) diff --git a/etc/neutron/rootwrap.d/l3.filters b/etc/neutron/rootwrap.d/l3.filters index 6b311e43811..3fa540fee89 100644 --- a/etc/neutron/rootwrap.d/l3.filters +++ b/etc/neutron/rootwrap.d/l3.filters @@ -28,7 +28,6 @@ kill_radvd_script: CommandFilter, radvd-kill, root # ip_lib ip: IpFilter, ip, root -find: RegExpFilter, find, root, find, /sys/class/net, -maxdepth, 1, -type, l, -printf, %.* ip_exec: IpNetnsExecFilter, ip, root # l3_tc_lib diff --git a/etc/neutron/rootwrap.d/linuxbridge-plugin.filters b/etc/neutron/rootwrap.d/linuxbridge-plugin.filters index 5c63b896e5a..497d225d9a1 100644 --- a/etc/neutron/rootwrap.d/linuxbridge-plugin.filters +++ b/etc/neutron/rootwrap.d/linuxbridge-plugin.filters @@ -17,5 +17,4 @@ sysctl: CommandFilter, sysctl, root # ip_lib ip: IpFilter, ip, root -find: RegExpFilter, find, root, find, /sys/class/net, -maxdepth, 1, -type, l, -printf, %.* ip_exec: IpNetnsExecFilter, ip, root diff --git a/etc/neutron/rootwrap.d/openvswitch-plugin.filters b/etc/neutron/rootwrap.d/openvswitch-plugin.filters index e5290243be8..083f01a1ccf 100644 --- a/etc/neutron/rootwrap.d/openvswitch-plugin.filters +++ b/etc/neutron/rootwrap.d/openvswitch-plugin.filters @@ -19,7 +19,6 @@ ovsdb-client: CommandFilter, ovsdb-client, root # ip_lib ip: IpFilter, ip, root -find: RegExpFilter, find, root, find, /sys/class/net, -maxdepth, 1, -type, l, -printf, %.* ip_exec: IpNetnsExecFilter, ip, root # needed for FDB extension