The LXD profiles are still available on disk in /var/lib/lxd/security/apparmor but I'm not sure we'll be able to easily fix all those processes that now got relabeled...
It may be simpler for the advisory to recommend all LXD users restart all their containers which will get LXD to regenerate and load the apparmor profile.
Something like "sudo lxd shutdown && sudo lxd activateifneeded" should do the trick, though note that having a maintainer script do so isn't a good idea as it'd be equivalent to having a maintainer script issuing random "reboot" commands to remote hosts.
The LXD profiles are still available on disk in /var/lib/ lxd/security/ apparmor but I'm not sure we'll be able to easily fix all those processes that now got relabeled...
It may be simpler for the advisory to recommend all LXD users restart all their containers which will get LXD to regenerate and load the apparmor profile.
Something like "sudo lxd shutdown && sudo lxd activateifneeded" should do the trick, though note that having a maintainer script do so isn't a good idea as it'd be equivalent to having a maintainer script issuing random "reboot" commands to remote hosts.