This is somewhat a long shot, but I wanted to know if someone could point to the set of Linux kernel patches that would be required to enable strict confinement of snapd.
It seems @abeato, while trying to create kernel snap for the Jetson platform, kept a large set of patches for kernel 4.9 https://github.com/alfonsosanchezbeato/jetson-kernel-snap/tree/master/src/l4t_32.1.0/patch – I am curious if we could use only a subset of those patches to enable confinement.
We are trying to build a Yocto based image for Nvidia Xavier NX and need to enable snapd’s strict confinement.