Known problems
From MinorFs Wiki
- Unconfined processes may be able to sniff capabilities by parsing /proc/PID/*, if those capabilities are passed as commandline arguments or enviroment variables.
- The AppArmor profiles sugest more controll than there is actualy there as AppArmor 2.x does not actualy mediate symbolic link access. This should be fixed when the 3.x versions of AppArmor come out.
