The proper way to do this would be to use pam_apparmor, similar to how selinux is doing this, through systemd --user
/etc/pam.d/systemd-user
However currently this would require updating to a new version of pam_apparmor OR confining systemd to define hats and potentially other setup, which is probably something we are not ready to do just yet.
The proper way to do this would be to use pam_apparmor, similar to how selinux is doing this, through systemd --user pam.d/systemd- user
/etc/
However currently this would require updating to a new version of pam_apparmor OR confining systemd to define hats and potentially other setup, which is probably something we are not ready to do just yet.