Check the status of apparmor:
sudo systemctl status apparmor
Check all the loaded profiles:
sudo aa-status
Install aa-genprof
and other utility packages:
sudo apt install apparmor-utils
Generate a profile for nano
text editor:
sudo aa-genprof nano
Restart apparmor to load the profile:
sudo systemctl restart apparmor
Disable nano
profile:
sudo aa-disable /etc/apparmor.d/usr.bin.nano
# sudo ln -s /etc/apparmor.d/usr.bin.nano /etc/apparmor.d/disable/usr.bin.nano
Enable nano
profile:
sudo rm /etc/apparmor.d/disable/usr.bin.nano
Move nano
profile to complain mode:
sudo aa-complain /etc/apparmor.d/usr.bin.nano
Move nano
profile to enforce mode:
sudo aa-enforce /etc/apparmor.d/usr.bin.nano
Reload apparmor config to kernal:
sudo apparmor_parser -r /etc/apparmor.d/usr.bin.nano
Remove the nano
profile:
sudo apparmor_parser -R /etc/apparmor.d/usr.bin.nano