Apparmor restrict unpriv editor (5.0-edge) #248
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Ubuntu Mantic
23.10
kernels before6.5.0-14
(and maybe earlier) have/proc/sys/kernel/apparmor_restrict_unprivileged_userns
and/proc/sys/kernel/apparmor_restrict_unprivileged_unconfined
only root accessible.While LXD can disable those restrictions to make unpriv containers work, the builtin editors used as fallback through unshare might trip into those files and cause noisy errors. Since the updated kernels have the restriction disabled by default and LXD disable them anyway, let's avoid the noisy errors and stop trying to read them in the fallback editor.
This is a cherry-pick from
latest-edge
: