Add a note about still enforcing deny rules to aa-complain manpage

This behaviour makes sense (for example to force the confined program to
use a fallback path), but is probably surprising for users, so we should
document it.

References: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=826218#37


Acked-by: John Johansen <john.johansen@canonical.com> for trunk, 2.10 and 2.9
This commit is contained in:
Christian Boltz 2016-06-05 23:43:55 +02:00
parent 1d8e388c93
commit 9d8340a8b3

View file

@ -41,6 +41,8 @@ B<aa-complain> is used to set the enforcement mode for one or more profiles to I
In this mode security policy is not enforced but rather access violations
are logged to the system log.
Note that 'deny' rules will be enforced even in complain mode.
=head1 BUGS
If you find any bugs, please report them at