# create subuid/subgui map for root
# (to run unprivileged containers as root)
usermod -v 100000-165535 -w 100000-165535 root
+
+ deb-systemd-invoke reload-or-try-restart lxc.service
;;
abort-upgrade|abort-remove|abort-deconfigure)
--- /dev/null
+From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
+From: Wolfgang Bumiller <w.bumiller@proxmox.com>
+Date: Wed, 10 Jul 2019 14:29:54 +0200
+Subject: [PATCH] init: add ExecReload to lxc.service to only reload profiles
+
+Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
+---
+ config/init/systemd/lxc.service.in | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/config/init/systemd/lxc.service.in b/config/init/systemd/lxc.service.in
+index 77541917e..e4c086e0a 100644
+--- a/config/init/systemd/lxc.service.in
++++ b/config/init/systemd/lxc.service.in
+@@ -10,6 +10,7 @@ RemainAfterExit=yes
+ ExecStartPre=@LIBEXECDIR@/lxc/lxc-apparmor-load
+ ExecStart=@LIBEXECDIR@/lxc/lxc-containers start
+ ExecStop=@LIBEXECDIR@/lxc/lxc-containers stop
++ExecReload=@LIBEXECDIR@/lxc/lxc-apparmor-load
+ # Environment=BOOTUP=serial
+ # Environment=CONSOLETYPE=serial
+ Delegate=yes
+--
+2.20.1
+
pve/0006-PVE-Config-namespace-separation.patch
pve/0007-PVE-Up-possibility-to-run-lxc-monitord-as-a-regular-.patch
pve/0008-PVE-Config-Disable-lxc.monitor-cgroup.patch
+pve/0009-init-add-ExecReload-to-lxc.service-to-only-reload-pr.patch
extra/0001-conf-use-SYSERROR-on-lxc_write_to_file-errors.patch
extra/0002-Revert-conf-remove-extra-MS_BIND-with-sysfs-mixed.patch
extra/0003-CVE-2019-5736-runC-rexec-callers-as-memfd.patch
dh_apparmor -p lxc-pve --profile-name=lxc-containers
dh_install --fail-missing
-override_dh_systemd_start:
- dh_systemd_start --no-restart-on-upgrade
+override_dh_installsystemd:
+ dh_installsystemd -plxc-pve -r lxc-monitord.service lxc-net.service
+ dh_installsystemd -plxc-pve -r --no-restart-after-upgrade lxc.service