I think the apparmor issue should be filed as a separate bug. The issue there is that systemd has mounted / as MS_SHARED, so lxc is having to remount / as rslave. The apparmor policy will need to be updated to allow that. Ideally we can wait to allow that until the apparmor parser properly parses the mounts propagation mount_options, so we don't have to allow lxc-start to remount / in other ways.
I think the apparmor issue should be filed as a separate bug. The issue there is that systemd has mounted / as MS_SHARED, so lxc is having to remount / as rslave. The apparmor policy will need to be updated to allow that. Ideally we can wait to allow that until the apparmor parser properly parses the mounts propagation mount_options, so we don't have to allow lxc-start to remount / in other ways.