Yes. I’ve tested it.
The main reason for this is so we can get rid of the systemd-sysctl profile so even if systemd-sysctl is compromised, it can’t change sysctls.
Yes. Most apparmor-profile-everything users will be using security-misc anyway.
Yes. I’ve tested it.
The main reason for this is so we can get rid of the systemd-sysctl profile so even if systemd-sysctl is compromised, it can’t change sysctls.
Yes. Most apparmor-profile-everything users will be using security-misc anyway.