To disable set kernel/unprivileged_userns_apparmor_policy = 0
Signed-off-by: John Johansen <john.johansen@canonical.com>
Signed-off-by: Leann Ogasawara <leann.ogasawara@canonical.com>
Signed-off-by: Tim Gardner <tim.gardner@canonical.com>
#include "include/policy_unpack.h"
#include "include/resource.h"
-int unprivileged_userns_apparmor_policy = 0;
+int unprivileged_userns_apparmor_policy = 1;
/* Note: mode names must be unique in the first character because of
* modechrs used to print modes on compound labels on some interfaces