touch-packages team mailing list archive
-
touch-packages team
-
Mailing list archive
-
Message #100298
[Bug 1272028] Re: remount, not honored on bind mounts
I just hit this myself with AppArmor 2.9.1 in Debian wheezy. Has this
been fixed upstream? I've attached a minimal reproduction.
** Attachment added: "minimal reproduction: application and apparmor profile"
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1272028/+attachment/4456972/+files/bind-remount-repro.tar.gz
--
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to apparmor in Ubuntu.
https://bugs.launchpad.net/bugs/1272028
Title:
remount, not honored on bind mounts
Status in apparmor package in Ubuntu:
Expired
Status in apparmor source package in Precise:
Expired
Status in apparmor source package in Trusty:
Expired
Status in apparmor source package in Utopic:
Expired
Bug description:
I was trying to run docker in a nested container. docker wants to
remount a bind-mounted dir as ro. Audit log showed this failed. I
first tried to add more specific rules, but when those did not work i
tried just
remount,
in the policy. Still the mount was denied. Finally when I added
'mount,', it worked.
Ideally I would be able to say
remount options=(ro,bind) -> /var/lib/docker/**/,
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1272028/+subscriptions