This is fixed in 2.10 and the to-be-released 2.9.3 for hats, and also for subprofiles _if you call "aa-complain /etc/apparmor.d/usr.bin.profilename".
If you use "aa-complain /usr/bin/somebinary", flags of subprofiles won't be changed (that's something I still need to fix). This also affects creating child profiles with aa-genprof, which will currently stay in complain mode.
This is fixed in 2.10 and the to-be-released 2.9.3 for hats, and also for subprofiles _if you call "aa-complain /etc/apparmor. d/usr.bin. profilename" .
If you use "aa-complain /usr/bin/ somebinary" , flags of subprofiles won't be changed (that's something I still need to fix). This also affects creating child profiles with aa-genprof, which will currently stay in complain mode.