From a8704556da0c3113358644fb522a4c522c9c06fb Mon Sep 17 00:00:00 2001 From: Simon Fels Date: Sun, 4 Dec 2016 17:07:44 +0100 Subject: [PATCH] Unload AppArmor profile for container management process If we run the management process with the AppArmor profile loaded from snap-confine various ashmem/binder operations are failing with permission denied errors. To workaround this until this problem is fixed we simply unload the AppArmor profile and continue to execute completely without any profile loaded. --- scripts/container-manager.sh | 2 +- snapcraft.yaml | 4 ++++ 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/scripts/container-manager.sh b/scripts/container-manager.sh index b642187..60a4327 100755 --- a/scripts/container-manager.sh +++ b/scripts/container-manager.sh @@ -29,4 +29,4 @@ chmod 666 /dev/ashmem # this path. mkdir -p $SNAP_COMMON/lxc -exec $SNAP/bin/anbox-wrapper.sh container-manager +exec $SNAP/usr/sbin/aa-exec -p unconfined -- $SNAP/bin/anbox-wrapper.sh container-manager diff --git a/snapcraft.yaml b/snapcraft.yaml index 771bc80..a066de7 100644 --- a/snapcraft.yaml +++ b/snapcraft.yaml @@ -36,6 +36,10 @@ parts: - bin/anbox-bridge.sh - bin/anbox-wrapper.sh - bin/container-manager.sh + apparmor: + plugin: nil + stage-packages: + - apparmor lxc: source: git://github.com/morphis/lxc source-branch: snappy-support