Comment 3 for bug 1867216

Revision history for this message
Jamie Strandboge (jdstrand) wrote :

I'm not sure we would want to add 'unix (bind) addr=auto,' to the default policy. For snapd, it seems we could add the rule to the docker-support interface (I don't know that another flavor is warranted for that)

I'm hesitant by default in apparmor abstractions or the snapd default template/auto-connected interfaces because the rule isn't very specific so adding it by default when most applications wouldn't need it opens up the potential for abuse. If this changes and there are many common use cases, we could revisit.