Merge lp:~serge-hallyn/ubuntu/trusty/lxc/lxc.aa-libvirt into lp:~ubuntu-branches/ubuntu/trusty/lxc/trusty
Proposed by
Serge Hallyn
Status: | Needs review |
---|---|
Proposed branch: | lp:~serge-hallyn/ubuntu/trusty/lxc/lxc.aa-libvirt |
Merge into: | lp:~ubuntu-branches/ubuntu/trusty/lxc/trusty |
Diff against target: |
36 lines (+17/-1) 2 files modified
debian/apparmor/abstractions-lxc-container-base (+7/-1) debian/changelog (+10/-0) |
To merge this branch: | bzr merge lp:~serge-hallyn/ubuntu/trusty/lxc/lxc.aa-libvirt |
Related bugs: |
Reviewer | Review Type | Date Requested | Status |
---|---|---|---|
Stéphane Graber | Pending | ||
Review via email: mp+193622@code.launchpad.net |
Description of the change
Allow write access under /sys/class/net and /sys/device/
To post a comment you must log in.
Unmerged revisions
- 308. By Serge Hallyn
-
debian/
apparmor/ abstractions- lxc-container- base: allow writes to
/sys/class/net/*and /sys/devices/virtual/ net/**. This is to allow
libvirt to set ip_forward on virbr0 which it creates. Note this is
safe because the container has it's own private view of those
directories.
FWIW, looks good to me. AppArmor needs a better way to express this.
Thanks