tree 36bcfa8e0cc7930b046a204df4685e52e34c16b8
parent 144656251d63284d22451af1b4f6b350e893f44a
author John Johansen <john.johansen@canonical.com> 1494417334 -0700
committer John Johansen <john.johansen@canonical.com> 1494460571 -0700

apparmor: virtualize the policy/ directory

virtualize the apparmor policy/ directory so that the current namespace
affects what part of policy is seen. This is done by

 * creating a new apparmorfs filesystem
 * creating a magic symlink from securityfs to the correct apparmorfs
   file in the tree (similar to nsfs use).

apparmor fs data and fns also get renamed some to help indicate where
they are used

  aafs - special magic apparmorfs
  aa_sfs - for fns/data that go into securityfs
  aa_fs - for fns/data that may be used in the either of aafs or securityfs

Signed-off-by: John Johansen <john.johansen@canonical.com>
Reviewed-by: Seth Arnold <seth.arnold@canonical.com>
