Given that we now have improvements to the general machinery of apparmor profiles for specific situations (e.g. the NFS work) we could look at attempting another fix for encrypted home partition.
One more issue that we had last time is that the state does not currently store flags (e.g. try) per revision very well so we may need to be more open if _any_ snap is in try mode. This will need a security review.
Given that we now have improvements to the general machinery of apparmor profiles for specific situations (e.g. the NFS work) we could look at attempting another fix for encrypted home partition.
One more issue that we had last time is that the state does not currently store flags (e.g. try) per revision very well so we may need to be more open if _any_ snap is in try mode. This will need a security review.