Commit 833bf9c2 by Serge Hallyn

allow cgroupfs mounts under /sys/fs/cgroup

Systemd needs to be able to do these, and it does not bypass any of our apparmor rules. Signed-off-by: 's avatarSerge Hallyn <serge.hallyn@ubuntu.com>
parent fe3c80af
......@@ -86,4 +86,5 @@
deny /sys/firmware/efi/efivars/** rwklx,
deny /sys/kernel/security/** rwklx,
mount options=(move) /sys/fs/cgroup/cgmanager/ -> /sys/fs/cgroup/cgmanager.lower/,
mount fstype=cgroup -> /sys/fs/cgroup/**,
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment