Skip to content
This repository has been archived by the owner on Apr 6, 2022. It is now read-only.

Enable Apparmor Confinement #36

Closed
wants to merge 6 commits into from

Conversation

om26er
Copy link
Contributor

@om26er om26er commented Aug 18, 2021

This adds snapd strict confinement for Linux 5.4, it includes

  • linux-yocto
  • linux-raspberrypi

Patches are stolen from https://forum.snapcraft.io/t/apparmor-kernel-patches-for-5-x-kernels/19955/3

Also deletes unused patches and updates snapd to 2.51.5

This was referenced Aug 18, 2021
@om26er
Copy link
Contributor Author

om26er commented Aug 18, 2021

I think we should change the snappy.cfg to make SQUASHFS support statically into the kernel instead of loading it as a module.

Reason: If a yocto system wants to boot from SquashFS (CONFIG_SQUASHFS=y), that will break the snapd build because kernel-module-squashfs won't be found

@bboozzoo bboozzoo self-requested a review August 19, 2021 05:05
@asimfarooq5
Copy link

Is there an update to this, it would be really great to have confinement working

@om26er
Copy link
Contributor Author

om26er commented Sep 22, 2021

ping @bboozzoo, did you get a chance to look at this PR ?

Ultimately I would like to help maintain this project. We have a bunch of other improvements that we'd like to contribute to this project.

@om26er
Copy link
Contributor Author

om26er commented Dec 22, 2021

ping @bboozzoo

@bboozzoo
Copy link
Collaborator

bboozzoo commented Apr 6, 2022

The repo has moved to https://github.com/snapcore/meta-snapd. Please file an issue there.

@bboozzoo bboozzoo closed this Apr 6, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants