Переглянути джерело

Revert "Introduce a dedicated unconfined AA policy"

This reverts commit 87376c3add7dcd48830060652554e7ae43d11881.

Signed-off-by: David Calavera <david.calavera@gmail.com>
David Calavera 10 роки тому
батько
коміт
94ab0d312f
2 змінених файлів з 1 додано та 13 видалено
  1. 0 12
      contrib/apparmor/docker
  2. 1 1
      daemon/execdriver/native/create.go

+ 0 - 12
contrib/apparmor/docker

@@ -23,15 +23,3 @@ profile docker-default flags=(attach_disconnected,mediate_deleted) {
   deny /sys/firmware/efi/efivars/** rwklx,
   deny /sys/firmware/efi/efivars/** rwklx,
   deny /sys/kernel/security/** rwklx,
   deny /sys/kernel/security/** rwklx,
 }
 }
-
-profile docker-unconfined flags=(attach_disconnected,mediate_deleted) {
-  #include <abstractions/base>
-
-  network,
-  capability,
-  file,
-  umount,
-  mount,
-  pivot_root,
-  change_profile -> *,
-}

+ 1 - 1
daemon/execdriver/native/create.go

@@ -198,7 +198,7 @@ func (d *driver) setPrivileged(container *configs.Config) (err error) {
 	container.Devices = hostDevices
 	container.Devices = hostDevices
 
 
 	if apparmor.IsEnabled() {
 	if apparmor.IsEnabled() {
-		container.AppArmorProfile = "docker-unconfined"
+		container.AppArmorProfile = "unconfined"
 	}
 	}
 
 
 	return nil
 	return nil