Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
interfaces/builtin: add exec "/bin/runc" to docker-support
Newer runC applied further improvements to their CVE-2019-5736 mitigation in opencontainers/runc#1984 which change the nature of our apparmor denial from `/` to `/bin/runc` (which I have also commented on https://bugs.launchpad.net/apparmor/+bug/1820344 about). See also #6610. (originally from Tianon Gravi, but re-committed due to CLA issues with the PR checks) Signed-off-by: Ian Johnson <ian.johnson@canonical.com>
- Loading branch information