Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
AppArmor: silence denial of sys_ptrace capability
We already allow ptrace for its relevant subprocesses via ptrace rules, and I'm unsure if the full capability is really needed. I see lots of other profiles which have ptrace rules without the capability so I guess not. And I wonder if allowing the capability allows ptrace for arbitrary processes, which would be really bad. So let's assume it's not needed and we'll see what happens.
- Loading branch information