Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow rootless AppArmor #1572

Merged
merged 2 commits into from
Aug 16, 2023

Commits on Jul 20, 2023

  1. Revert "Revert "Allow rootless containers to use AppArmor profiles""

    This reverts commit d167b7f.
    
    Signed-off-by: Will Shand <[email protected]>
    kernelmethod committed Jul 20, 2023
    Configuration menu
    Copy the full SHA
    8ec093a View commit details
    Browse the repository at this point in the history
  2. Change default profile to unconfined; remove CheckProfileAndLoadDefault

    Set the default AppArmor profile to unconfined; see the following
    issues:
    
    - containers#958
    - containers/podman#15874
    
    Based on the discussion there, distros that use AppArmor should supply
    their own AppArmor profile and set it in a default containers.conf,
    since there is no way to load AppArmor profiles rootlessly.
    
    Signed-off-by: Will Shand <[email protected]>
    kernelmethod committed Jul 20, 2023
    Configuration menu
    Copy the full SHA
    5c25c1c View commit details
    Browse the repository at this point in the history