3 ms·
The chief problem with AppArmor is that its primary mechanism of identifying objects in the system (to which relevant policy rules are applied) relies on paths.
by ENOTTY 7y ago
The chief problem with AppArmor is that its primary mechanism of identifying objects in the system (to which relevant policy rules are applied) relies on paths. In Linux, paths are not usable as strong identifiers because Linux provides a variety of ways to alias those objects. Additionally, some objects that deserve scrutiny from a mandatory access control perspective don't map cleanly to paths.