[apparmor] Proposal - revert chroot_relative changes for 2.8

John Johansen john.johansen at canonical.com
Mon Mar 12 23:25:39 UTC 2012


We had planned to transition to chroot relative profiles by default in 2.8
but I don't believe we are ready for this, yet.

chroot rules did not make it into 2.8 necessitating any profile confining a
task which uses chroot use the namespace_relative flag.

Nor do we have solution yet for dealing with chroot changes from unconfined
meaning we need to at a minimum revert the changes for unconfined.

As such I think it makes more sense to make this transition in 3.0 and keep
the 2.x series semantically consistent.



More information about the AppArmor mailing list