LXC is launching the container under an apparmor profile and all
processing within that container end up having the same profile. You
currently cannot have separate and distinct host policy and container
policy in the form that unity8 lxc is currently looking for. This
requires namespace stacking support in AppArmor (and kernel LSMs in
general)-- this is being worked on but won't be available for a while.
OA could be modified (at least for unity8 lxc) to treat "lxc-container-
default-with-nesting" like you do as unconfined. Or unity8 lxc could run
under unconfined instead of "lxc-container-default-with-nesting". This
would workaround the OA part, but I have little confidence that unity8
lxc would be able to launch and use applications, at least not without
changes to UAL to launch everything unconfined (which probably defaults
the purposes of testing an app within unity8 lxc).

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1466009

Title:
  Cannot add U1 account on Unity8 Desktop

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor-easyprof-ubuntu/+bug/1466009/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to