Hi,

After some AppArmor upgrade in Sid I've discovered that "firefox" profile is 
now duplicate.

Also, started to see some strange "flatpak", "busybox" errors in bash 
terminal...

1. Apparently, now there are bunch of new profiles, like /etc/apparmor.d/firefox, that conflicted with my own /etc/apparmor.d/usr.bin.firefox.

2. Apparently, my long-practiced "tradition" to invoke `aa-enforce /etc/apparmor.d/*` after every apparmor[-profiles] package upgrade (due to usr.bin.ping-and-friends becoming "complain" again), is now seemingly ill-advised? Enforcing all these new, almost-empty "uncofined" profiles makes sort of havoc...

So,

a). Could some one please bring me back into the loop, what's it all about?

b). How should user enable proper custom firefox profile correctly?

        aa-disable /etc/apparmor.d/firefox, and enforce 
/etc/apparmor.d/usr.bin.firefox?

        Or overwrite /etc/apparmor.d/firefox after every upgrade?

        Or is there some sort of new overriding feature I don't know to make 
these new profiles inactive while custom one active?

Thanks.


[0] https://salsa.debian.org/apparmor-team/apparmor/-/blob/8c785a5fb707253fb46213e0648d19b64631de83/profiles/apparmor.d/firefox



Reply via email to