Unload AppArmor profile for container management process

If we run the management process with the AppArmor profile loaded
from snap-confine various ashmem/binder operations are failing with
permission denied errors. To workaround this until this problem
is fixed we simply unload the AppArmor profile and continue to
execute completely without any profile loaded.
This commit is contained in:
Simon Fels 2016-12-04 17:07:44 +01:00
commit a8704556da
2 changed files with 5 additions and 1 deletions

View file

@ -29,4 +29,4 @@ chmod 666 /dev/ashmem
# this path.
mkdir -p $SNAP_COMMON/lxc
exec $SNAP/bin/anbox-wrapper.sh container-manager
exec $SNAP/usr/sbin/aa-exec -p unconfined -- $SNAP/bin/anbox-wrapper.sh container-manager

View file

@ -36,6 +36,10 @@ parts:
- bin/anbox-bridge.sh
- bin/anbox-wrapper.sh
- bin/container-manager.sh
apparmor:
plugin: nil
stage-packages:
- apparmor
lxc:
source: git://github.com/morphis/lxc
source-branch: snappy-support