Upstream AppArmor ships around 120 confining profiles, mostly for system and network services, so most applications run unconfined. apparmor.d, the main effort at comprehensive confinement, ships around 1,700 profiles but barely reaches production. No distribution enables it, for good reasons: enforcing them all is heavy on CPU and memory; many profiles are unused or too strict for interactive...
See More →