File: //proc/25618/root/lib/systemd/system/sysinit.target.wants/apparmor.service
[Unit]
Description=Load AppArmor profiles
DefaultDependencies=no
Before=sysinit.target
#After=systemd-journald-audit.socket
After=syno-rootfs-ready.target
ConditionSecurity=apparmor
IgnoreOnIsolate=yes
[Service]
Type=oneshot
ExecStart=/usr/syno/etc/rc.sysv/apparmor.sh reload
ExecReload=/usr/syno/etc/rc.sysv/apparmor.sh reload
# systemd maps 'restart' to 'stop; start' which means removing AppArmor confinement
# from running processes (and not being able to re-apply it later).
# Upstream systemd developers refused to implement an option that allows overriding
# this behaviour, therefore we have to make ExecStop a no-op to error out on the
# safe side.
#
# If you really want to unload all AppArmor profiles, run aa-teardown
ExecStop=/usr/bin/true
RemainAfterExit=yes
[X-Synology]