Bug#788656: lxc-start does not switch into AppArmor profiles for containers

2015-06-20 Thread Jason Briggs
okay sorry I missed a message in the other bug where it says this is apparmor kernel bug https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=750106#102 . You can see the content of "kernel-patches/3.12/0003-UBUNTU-SAUCE-apparmor-Add-the-ability-to-mediate-mou.patch" in the apparmor-2.9.0 source

Bug#788656: lxc-start does not switch into AppArmor profiles for containers

2015-06-20 Thread Jason Briggs
Upon further check I can confirm the message written by intrigeri in https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=750106#117 With: lxc-start -n myvm -l INFO -o ~/lxc_log.log my container logs: lxc-start 1434864946.838 INFO lxc_lsm - LSM security driver nop It must be because of t

Bug#788656: lxc-start does not switch into AppArmor profiles for containers

2015-06-14 Thread Jason Briggs
It still happens with the packages apparmor, apparmor-utils, apparmor-profiles, lxc from Sid installed in Jessie (after purged the old ones): apparmor 2.9.2-3 amd64 lxc1:1.0.7-3 At the time I could not get a fresh Stretch/Sid install to work so could not test that. --

Bug#788656: lxc-start does not switch into AppArmor profiles for containers

2015-06-13 Thread Jason Briggs
Minor correction to report, "It shows lxc-container-default as not loaded" means to say "It shows lxc-container-default as not loaded for the process" (the profile itself is loaded but not applied). In Jessie the package versions are: lxc 1:1.0.6-6 amd64 apparmor 2.9.0-3

Bug#788656: lxc-start does not switch into AppArmor profiles for containers

2015-06-13 Thread Pat Roberts
Package: lxc Version: 1:1.0.6-6 Severity: important Dear Maintainer, lxc-start does not seem to switch lxc containers to the default profile. aa-status reports lxc-start keeping the 'lxc-start' profile after the container has launched. I installed packages lxc, apparmor, apparmor-utils, apparmor