Commit 17f12d87 authored by Simon McVittie's avatar Simon McVittie

Remove <apparmor/> from default system.conf, session.conf

The AppArmor and SELinux modes both default to "enabled" (i.e.
enable it if and only if it is supported), so there is no need to
add their element to system.conf unless a system integrator wants
to set them to either required or disabled.

However, if we add <apparmor/> on upgrade from 1.9.10 to 1.9.12,
any subsequent attempts to reload bus configuration before the
next reboot will fail, because the dbus-daemon that is already
running does not support that element.

Bug: https://bugs.freedesktop.org/show_bug.cgi?id=89231Reviewed-by: default avatarTyler Hicks <tyhicks@canonical.com>
parent 65a84fd5
......@@ -25,9 +25,6 @@
<allow own="*"/>
</policy>
<!-- Enable AppArmor mediation when it is available -->
<apparmor mode="enabled"/>
<!-- Config files are placed here that among other things,
further restrict the above policy for specific services. -->
<includedir>session.d</includedir>
......
......@@ -97,9 +97,6 @@
send_interface="org.freedesktop.DBus.Debug.Stats"/>
</policy>
<!-- Enable AppArmor mediation when it is available -->
<apparmor mode="enabled"/>
<!-- Config files are placed here that among other things, punch
holes in the above policy for specific services. -->
<includedir>system.d</includedir>
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment