mirror of
https://gitlab.com/apparmor/apparmor
synced 2025-08-30 05:47:59 +00:00
Update AppArmorInSystemd
parent
dae14fe6d5
commit
44227c1f97
@ -19,10 +19,15 @@ Early policy loads are required to confine systemd, and other early services or
|
||||
|
||||
## Early policy loads
|
||||
|
||||
Requires
|
||||
Early policy must be precompiled binary (cache) that matches the kernel being booted and it must be placed in
|
||||
|
||||
```
|
||||
/etc/apparmor/earlypolicy
|
||||
```
|
||||
|
||||
The cache placed in ```/etc/apparmor/earlypolicy``` is expected to to conform to the per kernel directory hierarchy of regular cache.
|
||||
|
||||
|
||||
- all policy to be loaded to have precompiled cache that is available during early boot.
|
||||
- cache must be in a location that is available eg. /etc/apparmor.d/cache or /lib/apparmor/cache. Cache in /var/cache/apparmor/ can NOT be used.
|
||||
|
||||
????
|
||||
- Load is not parallel with other units
|
||||
|
Loading…
x
Reference in New Issue
Block a user