1
# Last Modified: Fri Apr 1 16:26:34 2016
2
# Mode: {{aa_profile_mode}}
3
#include <tunables/global>
5
/usr/bin/neutron-dhcp-agent {
6
#include <abstractions/base>
7
#include <abstractions/python>
8
#include <abstractions/nameservice>
10
/usr/bin/neutron-dhcp-agent r,
19
/var/lib/neutron/** rwk,
20
/var/log/neutron/** rwk,
21
/{,var/}run/neutron/** rwk,
22
/{,var/}run/lock/neutron/** rwk,
24
# Allow unconfined sudo to support oslo.rootwrap
25
# profile makes no attempt to restrict this as this
26
# is limited by the appropriate rootwrap configuration.
29
/usr/sbin/dnsmasq rix,
31
# Allow ip to run unrestricted for unpriviledged commands
37
# Required for parsing of managed process cmdline arguments
40
# Required for assessment of current state of networking
45
{% if ubuntu_release <= '12.04' %}
50
owner @{PROC}/@{pid}/mounts r,
51
owner @{PROC}/@{pid}/status r,
52
owner @{PROC}/@{pid}/ns/net r,