]> git.ipfire.org Git - thirdparty/lxc.git/commit
add lxc-default-cgns profile
authorSerge Hallyn <serge.hallyn@ubuntu.com>
Sun, 21 Feb 2016 23:38:11 +0000 (15:38 -0800)
committerSerge Hallyn <serge.hallyn@ubuntu.com>
Mon, 22 Feb 2016 04:44:59 +0000 (20:44 -0800)
commitdc76ac7ab5295b8ad40ac57c51e03da4dbd28479
tree8780108345fbd137b9248ef9b07fef29e9450910
parent82d97f87655222524ad583033b0ec9b778e2ddbc
add lxc-default-cgns profile

This isn't safe for privileged containers which do not use cgroup
namespaces, but is required for systemd containers with cgroup
namespaces.  So create a new profile for it which lxc will use as
the default when it knows it can.

Signed-off-by: Serge Hallyn <serge.hallyn@ubuntu.com>
config/apparmor/Makefile.am
config/apparmor/profiles/lxc-default-cgns [new file with mode: 0644]