2021-08-23 13:14:53 +00:00
|
|
|
//go:build !windows
|
|
|
|
// +build !windows
|
2016-12-19 12:22:45 +00:00
|
|
|
|
2018-02-05 21:05:59 +00:00
|
|
|
package daemon // import "github.com/docker/docker/daemon"
|
2016-12-19 12:22:45 +00:00
|
|
|
|
|
|
|
import (
|
|
|
|
"github.com/docker/docker/container"
|
2018-01-11 19:53:06 +00:00
|
|
|
"github.com/docker/docker/errdefs"
|
2016-12-19 12:22:45 +00:00
|
|
|
)
|
|
|
|
|
2019-08-09 10:33:15 +00:00
|
|
|
func (daemon *Daemon) saveAppArmorConfig(container *container.Container) error {
|
2019-11-27 14:43:53 +00:00
|
|
|
container.AppArmorProfile = "" // we don't care about the previous value.
|
2016-12-19 12:22:45 +00:00
|
|
|
|
|
|
|
if !daemon.apparmorEnabled {
|
|
|
|
return nil // if apparmor is disabled there is nothing to do here.
|
|
|
|
}
|
|
|
|
|
|
|
|
if err := parseSecurityOpt(container, container.HostConfig); err != nil {
|
2017-11-29 04:09:37 +00:00
|
|
|
return errdefs.InvalidParameter(err)
|
2016-12-19 12:22:45 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
if !container.HostConfig.Privileged {
|
|
|
|
if container.AppArmorProfile == "" {
|
2019-08-09 10:33:15 +00:00
|
|
|
container.AppArmorProfile = defaultAppArmorProfile
|
2016-12-19 12:22:45 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
} else {
|
2019-10-12 22:04:44 +00:00
|
|
|
container.AppArmorProfile = unconfinedAppArmorProfile
|
2016-12-19 12:22:45 +00:00
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|