mirror of
https://github.com/home-assistant/supervisor.git
synced 2026-09-29 11:38:42 +01:00
* Remove AppArmor profile file even when unloading fails OS Agent 1.14.0 (shipped with HAOS 18.3) validates AppArmor profiles with the actual apparmor_parser on both load and unload, and refuses to unload a profile file that defines unexpected or renamed profiles. remove_profile propagated that failure before unlinking the stored profile, so a file the agent rejects stayed in the AppArmor store directory, was retried on every startup, and could never be cleaned up through an uninstall. Log the unload failure and remove the stored profile file regardless. The profile may remain loaded in the kernel until the next reboot, but the file no longer lingers. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * Remove copied AppArmor profile when the OS Agent rejects the load load_profile copies the profile into the AppArmor store directory before asking the OS Agent to load it, so a profile rejected by the agent's parser validation (added in OS Agent 1.14.0) was left behind on disk. On the next startup load() re-reads the store directory and retries the rejected file, and it could never be cleaned up unless the app was uninstalled. Drop the in-memory profile entry and remove the copied file again when the agent rejects the load, keeping the entry if the file cannot be removed so a later remove_profile can still reach it. Transient load failures are left untouched so a good profile is not discarded. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>