Re: [lxc-users] apparmor profile for systemd containers (WAS: Fedora container thinks it is not running)

2014-05-28 Thread Serge Hallyn
Quoting Fajar A. Nugraha (l...@fajar.net): > (changed subject to match content) > > On Tue, May 27, 2014 at 11:10 PM, Michael H. Warfield > wrote: > > On Tue, 2014-05-27 at 15:33 +0700, Fajar A. Nugraha wrote: > >> On further test, this seems enough > > > >> ### > >> # cat lxc-default-with-syste

Re: [lxc-users] apparmor profile for systemd containers (WAS: Fedora container thinks it is not running)

2014-05-28 Thread Fajar A. Nugraha
On Thu, May 29, 2014 at 5:08 AM, Serge Hallyn wrote: > Quoting Fajar A. Nugraha (l...@fajar.net): > > (changed subject to match content) > > > > On Tue, May 27, 2014 at 11:10 PM, Michael H. Warfield > wrote: > > > On Tue, 2014-05-27 at 15:33 +0700, Fajar A. Nugraha wrote: > > >> On further test,

Re: [lxc-users] apparmor profile for systemd containers (WAS: Fedora container thinks it is not running)

2014-05-28 Thread Serge Hallyn
Quoting Fajar A. Nugraha (l...@fajar.net): > On Thu, May 29, 2014 at 5:08 AM, Serge Hallyn wrote: > > would systemd be happy with it being mounted by lxc using an > > lxc.mount.entry? I think that would be preferable to relaxing the > > apparmor policy. i.e. > > > > lxc.mount.entry = /sys/fs/cgro

Re: [lxc-users] apparmor profile for systemd containers (WAS: Fedora container thinks it is not running)

2014-05-28 Thread Fajar A. Nugraha
On Thu, May 29, 2014 at 10:58 AM, Serge Hallyn wrote: > Quoting Fajar A. Nugraha (l...@fajar.net): > > On Thu, May 29, 2014 at 5:08 AM, Serge Hallyn >wrote: > > > would systemd be happy with it being mounted by lxc using an > > > lxc.mount.entry? I think that would be preferable to relaxing the