Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
AppArmor: Allow sysfs for unprivileged containers (canonical#14010)
A new AppArmor includes security fixes and our ruleset become stricter, while the source code remains unchanged. sysfs was always available for unprivileged containers because of AppArmor bugs like [1]. Let's now allow it back by explicit rule. [1] https://bugs.launchpad.net/apparmor/+bug/1597017 Fixes: https://discourse.ubuntu.com/t/mount-root-sysfs-cannot-mount-sysfs-read-only-with-lxd-5-21-2-22f93f4-from-snap/47563
- Loading branch information