In newer kernels, AppArmor will reject attempts to send signals to a container because the signal originated from outside of that AppArmor profile. Correct this by allowing all unconfined signals to be received. Signed-off-by: Goldwyn Rodrigues <rgoldwyn@suse.com> Signed-off-by: Aleksa Sarai <asarai@suse.de> (cherry picked from commit 4822fb1e2423d88cdf0ad5d039b8fd3274b05401) Signed-off-by: Sebastiaan van Stijn <github@gone.nl> Upstream-commit: 67c602c3fe3d5d817fb7210e50d7ed1688b28801 Component: engine