Is apparmor.service working correctly?
Hello, I am just wondering if apparmor.service is working correctly on my test-notebook. `sudo systemctl status apparmor.service` states following: ``` ● apparmor.service - Load AppArmor profiles Loaded: loaded (/lib/systemd/system/apparmor.service; enabled; vendor preset: enabled) **Active: active (_exited_) since Sun 2022-01-30 11:02:39 CET; 5min ago** Docs: man:apparmor(7) https://gitlab.com/apparmor/apparmor/wikis/home/ Process: 1184 ExecStart=/lib/apparmor/apparmor.systemd reload (code=exited, status=0/SUCCESS) Main PID: 1184 (code=exited, status=0/SUCCESS) Jan 30 11:02:39 notebook systemd[1]: Starting Load AppArmor profiles... Jan 30 11:02:39 notebook apparmor.systemd[1184]: Restarting AppArmor Jan 30 11:02:39 notebook apparmor.systemd[1184]: Reloading AppArmor profiles Jan 30 11:02:39 notebook apparmor.systemd[1205]: Skipping profile in /etc/apparmor.d/disable: usr.bin.firefox Jan 30 11:02:39 notebook apparmor.systemd[1221]: Skipping profile in /etc/apparmor.d/disable: usr.sbin.rsyslogd Jan 30 11:02:39 notebook systemd[1]: Finished Load AppArmor profiles. ``` `sudo apparmor_status` states the following: ``` apparmor module is loaded. 107 profiles are loaded. 79 profiles are in enforce mode. /snap/core/12603/usr/lib/snapd/snap-confine /snap/core/12603/usr/lib/snapd/snap-confine//mount-namespace-capture-helper /snap/snapd/14295/usr/lib/snapd/snap-confine /snap/snapd/14295/usr/lib/snapd/snap-confine//mount-namespace-capture-helper /snap/snapd/14549/usr/lib/snapd/snap-confine /snap/snapd/14549/usr/lib/snapd/snap-confine//mount-namespace-capture-helper /usr/bin/evince /usr/bin/evince-previewer /usr/bin/evince-previewer//sanitized_helper /usr/bin/evince-thumbnailer /usr/bin/evince//sanitized_helper /usr/bin/lxc-start /usr/bin/man /usr/bin/pidgin /usr/bin/pidgin//sanitized_helper /usr/bin/totem /usr/bin/totem-audio-preview /usr/bin/totem-video-thumbnailer /usr/bin/totem//sanitized_helper /usr/lib/NetworkManager/nm-dhcp-client.action /usr/lib/NetworkManager/nm-dhcp-helper /usr/lib/connman/scripts/dhclient-script /usr/lib/cups/backend/cups-pdf /usr/lib/snapd/snap-confine /usr/lib/snapd/snap-confine//mount-namespace-capture-helper /usr/sbin/apt-cacher-ng /usr/sbin/cups-browsed /usr/sbin/cupsd /usr/sbin/cupsd//third_party /usr/sbin/tcpdump /{,usr/}sbin/dhclient chromium_browser//browser_java chromium_browser//browser_openjdk chromium_browser//sanitized_helper ippusbxd libvirtd libvirtd//qemu_bridge_helper man_filter man_groff multipass.dnsmasq multipass.focal.qemu-system-x86_64 nvidia_modprobe nvidia_modprobe//kmod snap-update-ns.android-studio snap-update-ns.code-insiders snap-update-ns.core snap-update-ns.flutter snap-update-ns.libreoffice snap-update-ns.multipass snap-update-ns.rpi-imager snap-update-ns.rubymine snap-update-ns.snap-store snap-update-ns.telegram-desktop snap.core.hook.configure snap.libreoffice.base snap.libreoffice.calc snap.libreoffice.draw snap.libreoffice.filebug snap.libreoffice.hook.configure snap.libreoffice.impress snap.libreoffice.libreoffice snap.libreoffice.math snap.libreoffice.writer snap.multipass.gui snap.multipass.hook.configure snap.multipass.hook.install snap.multipass.hook.post-refresh snap.multipass.hook.pre-refresh snap.multipass.hook.remove snap.multipass.multipass snap.multipass.multipassd snap.rpi-imager.rpi-imager snap.snap-store.hook.configure snap.snap-store.snap-store snap.snap-store.ubuntu-software snap.snap-store.ubuntu-software-local-file snap.telegram-desktop.hook.configure snap.telegram-desktop.telegram-desktop virt-aa-helper 28 profiles are in complain mode. /usr/bin/irssi /usr/sbin/dnsmasq /usr/sbin/dnsmasq//libvirt_leaseshelper avahi-daemon chromium_browser chromium_browser//chromium_browser_sandbox chromium_browser//lsb_release chromium_browser//xdgsettings identd klogd lsb_release mdnsd nmbd nscd ping smbd smbldap-useradd smbldap-useradd///etc/init.d/nscd snap.android-studio.android-studio snap.code-insiders.code-insiders snap.code-insiders.url-handler snap.flutter.dart snap.flutter.flutter snap.flutter.openurl snap.rubymine.rubymine syslog-ng syslogd traceroute 15 processes have profiles defined. 8 processes are in enforce mode. /usr/sbin/cups-browsed (1468) /usr/sbin/cupsd (1317) /usr/sbin/libvirtd (1538) libvirtd /snap/multipass/6408/usr/sbin/dnsmasq (2652) multipass.dnsmasq /snap/multipass/6408/usr/bin/qemu-system-x86_64 (2889) multipass.focal.qemu-system-x86_64 /snap/multipass/6408/bin/multipass.gui (3379) snap.multipass.gui /snap/multipass/6408/bin/multipassd (1475) snap.multipass.multipassd /snap/snap-store/558/usr/bin/snap-store (3380) snap.snap-store.ubuntu-software 7 processes are in complain mode. /usr/sbin/dnsmasq (1899) /usr/sbin/dnsmasq (1900) /usr/sbin/dnsmasq (1992) /usr/sbin/dnsmasq (2075) /usr/sbin/dnsmasq (2076) /usr/sbin/avahi-daemon (1312) avahi-daemon /usr/sbin/avahi-daemon (1372) avahi-daemon 0 processes are unconfined but have a profile defined. ```
issue