Commit Graph
1 Commits
Author SHA1 Message Date
Claude 351bfc47e8 Add fix-wolf-webview2-userns.sh — finish Kyber-in-Wolf
The WolfSteam app container already runs seccomp=unconfined + apparmor=unconfined
+ SYS_ADMIN, so the WebView2 CLONE_NEWUSER failure is gated at the HOST level by
kernel.apparmor_restrict_unprivileged_userns=1 (default-on since Ubuntu 23.10),
which overrides the unconfined container. This script relaxes that sysctl (and
the legacy unprivileged_userns_clone) persistently, then probes userns creation
on the host and inside the running container so login can complete without
leaving Wolf.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-23 14:25:56 +00:00