> There's apparently some support for loading per-namespace Apparmor policies, > but that means that the process is no longer confined by the sVirt policy
Would it not be possible to make the namespace handling be able to tell if a namespaced policy tries to expand beyond the original (in this case, sVirt) policy then just silently deny that expansion (and report it in the host)?
Namespaced LSM's
> but that means that the process is no longer confined by the sVirt policy
Would it not be possible to make the namespace handling be able to tell if a namespaced policy tries to expand beyond the original (in this case, sVirt) policy then just silently deny that expansion (and report it in the host)?