Re: [Bug 1227937] [NEW] lxc-start is unconfined but has a profile defined

2013-09-19 Thread Serge Hallyn
Thanks for reporting this bug. I can't reproduce this on a stock saucy system. How and when was that container created and started? Was it auto-started (since it's pid 471)? If you stop and restart the container, does that continue to be the case? Is it possible you had done unloaded all profi

[Bug 1227937] [NEW] lxc-start is unconfined but has a profile defined

2013-09-19 Thread Jamie Strandboge
Public bug reported: On today's ubuntu-system image (grouper) I noticed that lxc-start has a profile defined, but the process is not confined. Eg: $ sudo aa-status apparmor module is loaded. 20 profiles are loaded. 20 profiles are in enforce mode. ... /usr/bin/lxc-start ... lxc-container-de