apparmor/profiles/apparmor.d/slirp4netns
Akihiro Suda bf5db67284
profiles: slirp4netns: allow pivot_root
`pivot_root` is required for running `slirp4netns --enable-sandbox` inside LXD.
- https://github.com/rootless-containers/slirp4netns/issues/348
- https://github.com/rootless-containers/slirp4netns/blob/v1.3.1/sandbox.c#L101-L234

Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
2024-08-14 17:29:13 +09:00

16 lines
517 B
Text

# This profile allows everything and only exists to give the
# application a name instead of having the label "unconfined"
abi <abi/4.0>,
include <tunables/global>
profile slirp4netns /usr/bin/slirp4netns flags=(unconfined) {
userns,
# pivot_root is required for running `slirp4netns --enable-sandbox` inside LXD.
# https://github.com/rootless-containers/slirp4netns/issues/348
pivot_root,
# Site-specific additions and overrides. See local/README for details.
include if exists <local/slirp4netns>
}