Skip to content

Conversation

@timmc-edx
Copy link
Member

Two commits, see descriptions for details:

  • Rename apparmor profile
  • Allow some file writes

I've completed each of the following or determined they are not applicable:

  • Made a plan to communicate any major developer interface changes (or N/A)

AppArmor profiles are global within the OS, so we should use a name that is
better guaranteed to not conflict. Choosing an openedx prefix also gives
operators a hint when they're trying to manage installed profiles in the OS
and establishes precedent for future profiles.
- Specify `FSIZE` so that codejail executions can write a small amount
  (default is no writing to disk at all)
- Move `REALTIME` up to be next to `CPU`
@timmc-edx timmc-edx merged commit 9a2067b into master Mar 4, 2025
4 of 14 checks passed
@timmc-edx timmc-edx deleted the timmc/codejail-tweaks branch March 4, 2025 21:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants