Patrick, have you tested the Qubes-Whonix AppArmor instructions with dom0 upgraded to 4.14 kernel?
Even though kernelopts are set correctly as per:
The manual check in sys-whonix and Whonix-Workstation AppVM shows:
Not 0 as expected.
sudo aa-status shows “apparmor module is not loaded” in those AppVMs.
No evidence of AppArmor loading or profiles being enforced in logs as expected.
If this is a bug, this could affect a bunch of Whonix users when Qubes pushes 14.4 kernel, like I believe they intend to in the near term as it is next stable.