Code review comment for lp:~mdeslaur/upstart/apparmor-support

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

I'm not sure. Future versions of AppArmor may allow unprivileged users to load a new profile, and switching to a different profile may fail if the user is already confined by a restrictive AppArmor profile (with pam_apparmor for example). Also, I don't see any other mention of privileges in the man page, such as the setuid/setgid stanzas. While I could potentially add a "requires appropriate privileges" blurb, I believe it's assumed everywhere else.

« Back to merge proposal