Information
AppArmor profiles define what resources applications are able to access.
Security configuration requirements vary from site to site. Some sites may mandate a policy that is stricter than the default policy, which is perfectly acceptable. This item is intended to ensure that any policies that exist on the system are enforcing, actively denying policy violations rather than merely logging them.
Solution
First, identify any stub profiles present on the system:
# grep -rl "This profile exist only to give a name" /etc/apparmor.d/
For each stub profile returned, either:
- Develop the profile by adding appropriate file, capability, and network rules for the application, then enforce it individually:
# /usr/sbin/aa-enforce /etc/apparmor.d/<profile-name>
- Or remove the stub if the application is not present or needed on the system:
# apt remove <package-name>
Once all stub profiles have been developed and enforced, or removed, run the following to enforce all remaining profiles:
# /usr/sbin/aa-enforce /etc/apparmor.d/*
Note: The glob /etc/apparmor.d/* matches top-level profile files as well as subdirectories ( abstractions/, tunables/, abi/, local/ ). Passing a subdirectory to aa-enforce may produce warnings but does not affect profile enforcement. Any unconfined processes may need to have a profile created or activated for them and then be restarted.
Impact:
Setting AppArmor profiles to enforce mode causes policy violations to be denied rather than logged. Applications with incomplete or overly-restrictive profiles may fail or behave unexpectedly. Profiles should be tested in complain mode and tuned before being set to enforce.
Note: AppArmor 4, shipped with Debian 13, introduces "stub profiles" located in /etc/apparmor.d/ (for example, busybox ). Stub profiles contain only a userns, rule they assign a label to a process for user namespace tracking but intentionally have no file, capability, or network access rules. Enforcing a stub profile applies AppArmor's default-deny policy, causing all file access to be denied and the associated application to fail. All stub profiles carry the identifying comment: "This profile exist only to give a name rather than the label unconfined".
Stub profiles must be fully developed with appropriate file and capability rules before being set to enforce mode. See Additional Information for guidance on identifying and tuning stub profiles.