FYI, I clarified the description that the issue is for 'aa-exec', not
everything.
** Description changed:
- Somewhere between 3.13 and 4.4, the scrubbing behavior of ix changed.
- For example, on Ubuntu 12.04 and 14.04 we have:
+ Somewhere between 3.13 and 4.4, the scrubbing behavior of ix for aa
These seem like counter arguments. On the one hand you seem to say that
scrubbing is ok for ix and then change to suggest modifying ix to not
scrub and introduce Ix.
This bug is really about an inconsistency between 'ix' for normal
fork/exec where there is no scrubbing and 'ix' on aa-exec where th
Just wondering - if this bug survived so long without being noticed,
isn't it a sign that in most cases scrubbing doesn't hurt or is even a
good idea?
Should we introduce Ix to officially have a way to inherit with
scrubbing?
--
You received this bug notification because you are a member of Ubun
FYI, this was discovered because of https://forum.snapcraft.io/t/2-0
-lxd-snap-fails-on-sytems-with-partial-apparmor-support/4707
** Description changed:
- Somewhere between 3.13 and 4.4, the scrubbing behavior of ix changed
- when going through aa-exec. For example, on Ubuntu 12.04 and 14.04 we