Files
docker-cli/components/engine/daemon/execdriver
Eric Windisch 9f8e7b5fed Introduce a dedicated unconfined AA policy
By using the 'unconfined' policy for privileged
containers, we have inherited the host's apparmor
policies, which really make no sense in the
context of the container's filesystem.

For instance, policies written against
the paths of binaries such as '/usr/sbin/tcpdump'
can be easily circumvented by moving the binary
within the container filesystem.

Fixes GH#5490

Signed-off-by: Eric Windisch <eric@windisch.us>
Upstream-commit: 87376c3add7dcd48830060652554e7ae43d11881
Component: engine
2015-07-22 11:28:32 -04:00
..
2015-07-10 13:36:56 -07:00
2015-07-21 09:56:28 -07:00
2015-07-16 16:02:26 -07:00
2015-07-21 09:56:28 -07:00
2014-04-17 14:43:01 -07:00
2015-05-08 09:40:05 -07:00