Comment 6 for bug 1728551

Revision history for this message
Vincas Dargis (talkless) wrote : Re: [Bug 1728551] Re: Convert /sys to @{sys}

On 2017-12-04 16:52, Christian Boltz wrote:
> I'm afraid you have to coordinate the change better - declaring a
> variable twice causes a parser error:

Thanks! Duplicate rules manages to merge, but not variables...

1. We have to be aware for profiles that _already_ includes tunables/sys then...
"Downgrade" them to not use "@{sys}" (remove include "tunables/sys" too!).

2. Then, update "tunables/global" together with "apparmor.d/abstractios" and "apparmor.d/*" profiles in one go.

3. Finally, only after all these have been shipped on all relevant distributions, we can update profiles from
"profiles/extra" directory and "apparmor-profiles" repository, and the else (Libreoffice that has it's own, etc).