On Wed, 5 Jun 2019, John Johansen wrote: > This does rely on apparmor doing its own namespacing and bounding. LSM > stacking just allows us to start doing this with apparmor containers > on smack and selinux based systems. Ahh, ok, I thought you were using an LSM stack for each container. -- James Morris <jmorris@xxxxxxxxx>