Docker-DCO-1.1-Signed-off-by: Victor Vieux <vieux@docker.com> (github: vieux)
| ... | ... |
@@ -13,7 +13,7 @@ import ( |
| 13 | 13 |
) |
| 14 | 14 |
|
| 15 | 15 |
func IsEnabled() bool {
|
| 16 |
- if _, err := os.Stat("/sys/kernel/security/apparmor"); err == nil {
|
|
| 16 |
+ if _, err := os.Stat("/sys/kernel/security/apparmor"); err == nil && os.Getenv("container") == "" {
|
|
| 17 | 17 |
buf, err := ioutil.ReadFile("/sys/module/apparmor/parameters/enabled")
|
| 18 | 18 |
return err == nil && len(buf) > 1 && buf[0] == 'Y' |
| 19 | 19 |
} |