Control: tag -1 + patch
>> B) remove the AppArmor profile entirely and rely on seccomp instead
>> C) don't enable "no new privs" and rely on AppArmor instead
> I think B is fine given all the non-AppArmor hardening efforts Colin
> has been putting into man-db recently.
There we go: https://salsa.debian.org/debian/man-db/merge_requests/1
I've verified that upgrading from 2.8.0-1 successfully unloads the
profile on my system. I didn't test this upgrade path on a system
that has AppArmor disabled though.