Quick check if non-lXD environments are affected starting at Bionic to be sure: - Bionic - ok - Cosmic - ok - Cosmic with libvirt 4.6 - ok
So the special rule is only needed when stacking 1. apparmor controlled daemons 2. modifying mount namespaces of guests 3. inside containers
Yeah complexity FTW!
Quick check if non-lXD environments are affected starting at Bionic to be sure:
- Bionic - ok
- Cosmic - ok
- Cosmic with libvirt 4.6 - ok
So the special rule is only needed when stacking
1. apparmor controlled daemons
2. modifying mount namespaces of guests
3. inside containers
Yeah complexity FTW!