Comment 2 for bug 1748510

Revision history for this message
Seth Arnold (seth-arnold) wrote :

AppArmor intentionally does not mediate access(2) and similar system calls. While it might be feasible to give results for files, giving results for a directory would be error-prone.

We chose to err on the side of saying access(2) does not reflect AppArmor's mediation for the simplicity of the mental model.

Thanks