Skip to content

Remove {,lib/live/mount/overlay/} from the AppArmor profile for I2P

This adds noise that makes it harder to review/audit/debug the profile.

I think there are three cases:

  • Tails: not needed since we do alias / -> /lib/live/mount/overlay/
  • non-Tails Debian Live system: if they use AppArmor, they’ll need the same alias as well, so it’s not needed either
  • non-Live system: lib/live/mount/overlay/ should not be relevant

Parent Task: #7724

Original created by @intrigeri on 10924 (Redmine)

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information