Merge "V-51739: LSM device labeling exception"

This commit is contained in:
Jenkins 2015-10-15 20:41:43 +00:00 committed by Gerrit Code Review
commit 6a7cfb5eb6

View File

@ -0,0 +1,7 @@
**Exception**
Although SELinux works through a labeling system where every file (including
devices) receive a label, AppArmor works purely through policies without
labels. However, openstack-ansible does configure several AppArmor policies
to reduce the chances and impact of LXC container breakouts on OpenStack
hosts.