Permalink
Please sign in to comment.
Browse files
Enable snap-confine namespace sharing
This patch changes mount-support.[ch] a little so that there's no explicit unshare API anymore (this is handled by ns-support.h) and so that mount-suppor.h is really just about populating the namespace that is already provided. In addition, sc-main.c now uses SNAP_NAME to join or create a namespace group and if populates it if necessary. The apparmor profile is updated to let snap-confine perform the additional tasks. Signed-off-by: Zygmunt Krynicki <zygmunt.krynicki@canonical.com>
- Loading branch information...
Showing
with
86 additions
and 31 deletions.
- +5 −15 src/mount-support.c
- +0 −14 src/mount-support.h
- +16 −2 src/sc-main.c
- +65 −0 src/snap-confine.apparmor.in
0 comments on commit
865c5df