Known problems
From MinorFs Wiki
- Unconfined processes may be able to sniff capabilities by parsing /proc/PID/*, if those capabilities are passed as command line arguments or enviroment variables.
- The AppArmor profiles suggest more control than is actually there, as AppArmor 2.x does not actually mediate symbolic link access. This should be fixed when the 3.x versions of AppArmor come out.