nspawn: sync DeviceAllow= setting with systemd-nspawn@.service
authorYu Watanabe <watanabe.yu+github@gmail.com>
Mon, 9 Sep 2024 18:38:13 +0000 (03:38 +0900)
committerYu Watanabe <watanabe.yu+github@gmail.com>
Mon, 9 Sep 2024 19:38:11 +0000 (04:38 +0900)
commitb86b90cec59d8a41f8cf5e9797980e81bd18082b
treebe15b384ea03c8ca605c80f0b7e6a586b566c9f6
parent8b29949a4142318bacf3d30751aa37b8f29b5c1e
nspawn: sync DeviceAllow= setting with systemd-nspawn@.service

Follow-up for dc3223919f663b7c8b8d8d1d6072b4487df7709b.
Addresses https://github.com/systemd/systemd/pull/34067#discussion_r1748592958.

Otherwise, containers started with and without --keep-unit option run in
different device policies.
src/nspawn/nspawn-register.c
units/systemd-nspawn@.service.in