from prior discussions I understand that the problem is that it's not easy
(or nessasarily possible) to figure out the path to the fd, so what do you
check?
if the file has been removed there _is_ no path to the fd.
with hard links there could be many paths to the fd, the only way to find
them would be to search the entire filesystem.
as a result App Armor has decided not to try and address this, but is
documenting it as a limitation.
David Lang
-