This is due to a bug in upstream parser/rc.apparmor.functions because SFS_MOUNTPOINT is only set after is_apparmor_loaded() is called, but is_container_with_internal_policy() doesn't call it. /lib/apparmor/apparmor.systemd calls is_container_with_internal_policy() prior to apparmor_start() and it is only through apparmor_start() that is_apparmor_loaded() is called.
This is due to a bug in upstream parser/ rc.apparmor. functions because SFS_MOUNTPOINT is only set after is_apparmor_ loaded( ) is called, but is_container_ with_internal_ policy( ) doesn't call it. /lib/apparmor/ apparmor. systemd calls is_container_ with_internal_ policy( ) prior to apparmor_start() and it is only through apparmor_start() that is_apparmor_ loaded( ) is called.