Open AkihiroSuda opened 11 months ago
/etc/apparmor.d/usr.sbin.runc
from apparmor_4.0.0~alpha2-0ubuntu5_amd64.deb
:
abi <abi/4.0>,
include <tunables/global>
/usr/sbin/runc flags=(unconfined) {
userns,
# Site-specific additions and overrides. See local/README for details.
include if exists <local/usr.sbin.runc>
}
https://ubuntu.com/blog/ubuntu-23-10-restricted-unprivileged-user-namespaces
Probably we should provide an apparmor profile in contrib/