This does indeed seem to be the problem.  The current labeling done by
apparmor is not enough to avoid needing the mediate_deleted flag on the
lxc profiles.  Adding the flag will force apparmor to do a name lookup
for entries that have been deleted (the name can be reliably be
reconstructed), instead of using the default of the cached file label.

I have opened Bug #970647 for the failure to log rejects due to the
deleted entry logic.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/969299

Title:
  apparmor prevents dpkg-divert and localedef from working in a
  container

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/969299/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to