Restart entire container-manager script outside of AppArmor confinement
This commit is contained in:
parent
bfd0619d96
commit
d3af8a0732
1 changed files with 6 additions and 8 deletions
|
|
@ -27,6 +27,11 @@ else
|
||||||
ARCH="$SNAP_ARCH-linux-gnu"
|
ARCH="$SNAP_ARCH-linux-gnu"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# Re-exec outside of apparmor confinement
|
||||||
|
if [ -d /sys/kernel/security/apparmor ] && [ "$(cat /proc/self/attr/current)" != "unconfined" ]; then
|
||||||
|
exec /usr/sbin/aa-exec -p unconfined -- "$0" "$@"
|
||||||
|
fi
|
||||||
|
|
||||||
start() {
|
start() {
|
||||||
# Make sure our setup path for the container rootfs
|
# Make sure our setup path for the container rootfs
|
||||||
# is present as lxc is statically configured for
|
# is present as lxc is statically configured for
|
||||||
|
|
@ -40,13 +45,6 @@ start() {
|
||||||
# Ensure FUSE support for user namespaces is enabled
|
# Ensure FUSE support for user namespaces is enabled
|
||||||
echo Y | tee /sys/module/fuse/parameters/userns_mounts || echo "WARNING: kernel doesn't support fuse in user namespaces"
|
echo Y | tee /sys/module/fuse/parameters/userns_mounts || echo "WARNING: kernel doesn't support fuse in user namespaces"
|
||||||
|
|
||||||
# Only try to use AppArmor when the kernel has support for it
|
|
||||||
AA_EXEC="$SNAP/usr/sbin/aa-exec -p unconfined --"
|
|
||||||
if [ ! -d /sys/kernel/security/apparmor ]; then
|
|
||||||
echo "WARNING: AppArmor support is not available!"
|
|
||||||
AA_EXEC=""
|
|
||||||
fi
|
|
||||||
|
|
||||||
# liblxc.so.1 is in $SNAP/lib
|
# liblxc.so.1 is in $SNAP/lib
|
||||||
export LD_LIBRARY_PATH="$LD_LIBRARY_PATH:$SNAP/liblxc"
|
export LD_LIBRARY_PATH="$LD_LIBRARY_PATH:$SNAP/liblxc"
|
||||||
|
|
||||||
|
|
@ -77,7 +75,7 @@ start() {
|
||||||
EXTRA_ARGS="$EXTRA_ARGS --privileged"
|
EXTRA_ARGS="$EXTRA_ARGS --privileged"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
exec "$AA_EXEC" "$SNAP"/bin/anbox-wrapper.sh container-manager \
|
exec "$SNAP"/bin/anbox-wrapper.sh container-manager \
|
||||||
"$EXTRA_ARGS" \
|
"$EXTRA_ARGS" \
|
||||||
--data-path="$DATA_PATH" \
|
--data-path="$DATA_PATH" \
|
||||||
--android-image="$ANDROID_IMG" \
|
--android-image="$ANDROID_IMG" \
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue