It doesn't seem to only affect rsyslog as I have for example a shell script contained by an Apparmor profile and inside the container it doesn't work as it wants to read /bin/dash:
audit: type=1400 audit(1487935787.212:153): apparmor="DENIED" operation="file_mprotect" namespace="root//lxd-smb_<var-lib-lxd>" profile="/usr/local/bin/backuppc-wrapper" name="/bin/dash" pid=29187 comm="backuppc-wrappe" requested_mask="r" denied_mask="r" fsuid=165570 ouid=165536
It doesn't seem to only affect rsyslog as I have for example a shell script contained by an Apparmor profile and inside the container it doesn't work as it wants to read /bin/dash:
audit: type=1400 audit(148793578 7.212:153) : apparmor="DENIED" operation= "file_mprotect" namespace= "root// lxd-smb_ <var-lib- lxd>" profile= "/usr/local/ bin/backuppc- wrapper" name="/bin/dash" pid=29187 comm="backuppc- wrappe" requested_mask="r" denied_mask="r" fsuid=165570 ouid=165536