## AppArmor profile for lattisd, installed by the .deb at /etc/apparmor.d/lattisd.
##
## Why it exists. Ubuntu 23.10 and later set
## kernel.apparmor_restrict_unprivileged_userns=1. An unconfined binary may
## still create a user namespace, but the kernel then moves it to the
## `unprivileged_userns` label, which denies every capability inside. The
## chat sandbox (docs/chat-sandbox/README.md) needs CLONE_NEWPID, mounts, and
## pivot_root inside that namespace, and they all fail with EPERM. A profile
## keyed to the binary path that grants `userns` is the fix the distribution
## itself uses for bwrap and unshare. Measured in docs/chat-sandbox/NOTES.md.
##
## Shape. The daemon stays unconfined in every other respect: it spawns git,
## gh, coding agents, and MCP servers, and none of that should change. The
## one rule added is `userns`. A tighter two-profile shape, following
## /etc/apparmor.d/bwrap-userns-restrict, is possible later.
##
## The path must match where the package installs the daemon. The AppImage
## has no stable path, so it cannot carry a profile; the daemon's probe
## reports reduced isolation there.

abi <abi/4.0>,
include <tunables/global>

profile lattisd /opt/lattis/lattisd flags=(unconfined) {
  userns,

  include if exists <local/lattisd>
}
