Oliver Grawert [2015-05-21 12:54 +0200]:
> well, i meant more with not moving any files around at all but keep /etc
> as is and writable and then apply an "ACL mask" (or apparmor profile) to
> the content to allow write access for some of the files ...

With that we can't actually ship /etc/ in the image any more (unless
we have some fancy overlayfs, which we can't rely on), so we have to
copy them from somewhere inside the r/o image.

Also, you still need a pristine version of what should be in /etc so
that you can update the files in /etc/ on image updates.


