Commit 5f1dee3
committed
interfaces/builtin: add exec "/bin/runc" to docker-support
Newer runC applied further improvements to their CVE-2019-5736 mitigation in opencontainers/runc#1984 which change the nature of our apparmor denial from `/` to `/bin/runc` (which I have also commented on https://bugs.launchpad.net/apparmor/+bug/1820344 about).
See also canonical#6610.
(originally from Tianon Gravi, but re-committed due to CLA issues with the PR checks)
Signed-off-by: Ian Johnson <[email protected]>1 parent 4bb0643 commit 5f1dee3
1 file changed
+1
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
157 | 157 | | |
158 | 158 | | |
159 | 159 | | |
| 160 | + | |
160 | 161 | | |
161 | 162 | | |
162 | 163 | | |
| |||
0 commit comments