Check for AppArmor support before using aa-exec
This commit is contained in:
parent
d8612d3ef1
commit
d7ccae072e
1 changed files with 8 additions and 2 deletions
|
|
@ -28,8 +28,14 @@ start() {
|
||||||
# Ensure FUSE support for user namespaces is enabled
|
# Ensure FUSE support for user namespaces is enabled
|
||||||
echo Y | sudo tee /sys/module/fuse/parameters/userns_mounts || echo "WARNING: kernel doesn't support fuse in user namespaces"
|
echo Y | sudo tee /sys/module/fuse/parameters/userns_mounts || echo "WARNING: kernel doesn't support fuse in user namespaces"
|
||||||
|
|
||||||
exec $SNAP/usr/sbin/aa-exec -p unconfined -- \
|
# Only try to use AppArmor when the kernel has support for it
|
||||||
$SNAP/bin/anbox-wrapper.sh container-manager \
|
AA_EXEC="$SNAP/usr/sbin/aa-exec -p unconfined --"
|
||||||
|
if [ ! -d /sys/kernel/security/apparmor ]; then
|
||||||
|
echo "WARNING: AppArmor support is not available!"
|
||||||
|
AA_EXEC=""
|
||||||
|
fi
|
||||||
|
|
||||||
|
exec $AA_EXEC $SNAP/bin/anbox-wrapper.sh container-manager \
|
||||||
--data-path=$DATA_PATH \
|
--data-path=$DATA_PATH \
|
||||||
--android-image=$ANDROID_IMG
|
--android-image=$ANDROID_IMG
|
||||||
}
|
}
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue