Helo,
this is my first posting in this forum.
Some days ago I installed Endeavouros KDE Plasma Version 5.25.5 in a Virtualbox as a first approach to it and for to learn more about Arch step-by-step and to get updates faster for security reasons unlike other Arch forks.
Until now it works fine, except a problem with apparmor.
I want to use it together with Firejail.
My Kernel Version: 5.19.7-arch1-1 (64-bit)
I found some threads concerning apparmor errors e.g. like here:
but no solution for my problem.
I tried following commands and got error messages as listed:
aa-status
apparmor module is loaded.
apparmor filesystem is not mounted
follwing some hints in differnet threads to complete this line in grub.
Now, I have no more idea. Please let me know how to solve this error considering please that I am a newbie in Endeavouros in as a close Arch fork and have no experience until now with issues like Kernel compilation.
Thanks a lot in advance.
To integrate firejail with apparmor, you have to run this command only once: apparmor_parser -r /etc/apparmor.d/firejail-default
…before you run: sudo firecfg
Thanks a lot dalto and ivanhoe for reply and help!
I followed your instructions, dalto - and yes, now apparmor is running!
I used the apparmor parsing command, ivanhoe, but obviously firejail-default was implemented already before.
I am missing preconfigured apparmor profiles for Firefox, Thunderbird and Torbrowser
especially. Maybe Endeavouros users are used to install them by themselves?
Or have incompatibilities to be expected moreover using Apparmor and Firejail together for some applications? A hint in the wiki seems to point out you have to consider problems in some cases.
Arch and EndeavourOS don’t ship with apparmor so there are no profiles. You need to setup your own profiles. There are some predefined ones in AUR such as krathalans-apparmor-profiles-git but it is up to you if you want to use those or not.
Thanks again for reply, dalto.
I found it a bit different, because I could download apparmor (Arch Repo). After apparmor is working about 60 applications are listed running in enforce mode spontaneously.
But yes, as mentioned some are missing like Firefox e.g.