apparmor.d manpage does not make it clear that deny rules overrride allow rules
Bug #1397111 reported by
Steve Beattie
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
AppArmor |
New
|
Undecided
|
Unassigned |
Bug Description
The apparmor.d manpage should make explicit that deny rules override allow rules when writing policy. This makes it possible for modifications in local.d/ to restrict a distributed profile without needing to modify the profile directly.
To post a comment you must log in.