mirror_lxc/config/apparmor/abstractions
Wolfgang Bumiller e6ec0a9e71 apparmor: allow various remount,bind options
RW bind mounts need to be restricted for some paths in
order to avoid MAC restriction bypasses, but read-only bind
mounts shouldn't have that problem.

Additionally, combinations of 'nosuid', 'nodev' and
'noexec' flags shouldn't be a problem either and are
required with newer systemd versions, so let's allow those
as long as they're combined with 'ro,remount,bind'.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
2018-11-16 12:17:30 +01:00
..
container-base apparmor: allow various remount,bind options 2018-11-16 12:17:30 +01:00
container-base.in apparmor: allow various remount,bind options 2018-11-16 12:17:30 +01:00
start-container.in apparmor: account for specified rootfs path (closes #2617) 2018-09-20 15:56:05 -07:00