CR: P16g AppArmor Deployment — Verification
Pre-Change Checklist
| Check | Status |
|---|---|
|
[ ] |
|
[ ] |
|
[ ] |
|
[ ] |
All user processes have unrestricted access to |
[ ] |
Kernel has |
[ ] |
Post-Change Checklist
| Check | Status |
|---|---|
|
[ ] |
|
[ ] |
|
[ ] |
|
[ ] |
|
[ ] |
Boot parameters updated in all 3 entries (arch, fallback, LTS) |
[ ] |
|
[ ] |
Browser profiles (Firefox, Chrome, Chromium) in enforce mode with credential store denies |
[ ] |
|
[ ] |
Applications function normally under AppArmor confinement |
[ ] |
Verification Commands
| Check | Command | Expected |
|---|---|---|
LSM stack |
|
Includes |
Service active |
|
|
Profiles loaded |
|
>0 profiles in enforce/complain |
Boot parameter |
|
|
Credential deny |
|
>0 enforce-mode profiles |
Docker integration |
|
AppArmor listed as security option |