Ensure /proc and /sys are mounted in the container, otherwise
apparmor_enabled() will fail to find
/sys/module/apparmor/parameters/enabled
Signed-off-by: Dwight Engen <dwight.engen@oracle.com>
Signed-off-by: Serge Hallyn <serge.hallyn@ubuntu.com>
$rootfs/sbin \
$rootfs/usr/sbin \
$rootfs/proc \
+$rootfs/sys \
$rootfs/mnt \
$rootfs/tmp \
$rootfs/var/log \
# mount points
cat <<EOF >> $rootfs/etc/fstab
-proc /proc proc defaults 0 0
shm /dev/shm tmpfs defaults 0 0
EOF
echo "lxc.mount.entry = /$dir $dir none ro,bind 0 0" >> $path/config
fi
done
+ echo "lxc.mount.entry = /sys/kernel/security sys/kernel/security none ro,bind 0 0" >>$path/config
+ echo "lxc.mount.auto = proc:mixed sys" >>$path/config
}
usage()