the `patchShebangs` in `postPatch` is for tools that are invoked at
build-time. we don't want to patch the shebangs this early in the
derivation for anything that would later be installed, so scope it more
narrowly.
also be more hygienic with the shell-related `buildInputs`/`nativeBuildInputs`.
Upstream release: https://gitlab.com/apparmor/apparmor/-/releases/v4.1.0
Notable changes made to the packaging:
- apparmor-kernel-patches: drop. This was outdated and unused, and wouldn't even apply to any kernel anymore.
- aa-teardown: migrate to writeShellAPplication
- apparmor-*: migrate to by-name
- apparmor-*: enable checks and actually run checks
- libapparmor: test python module imports correctly
- libapparmor: no seperate $python output (makes no sense)