Merge "V-51739: LSM device labeling exception"
This commit is contained in:
commit
6a7cfb5eb6
7
doc/source/developer-notes/V-51379.rst
Normal file
7
doc/source/developer-notes/V-51379.rst
Normal file
@ -0,0 +1,7 @@
|
||||
**Exception**
|
||||
|
||||
Although SELinux works through a labeling system where every file (including
|
||||
devices) receive a label, AppArmor works purely through policies without
|
||||
labels. However, openstack-ansible does configure several AppArmor policies
|
||||
to reduce the chances and impact of LXC container breakouts on OpenStack
|
||||
hosts.
|
Loading…
Reference in New Issue
Block a user