Is there any indication Linux is going to adopt a pledge/unveil api in the near future? It's hard to place faith in systems like app armor that rely on system administrators to implement security guarantees.
Pledge/unveil would not help with the xz issue. AppArmor would.
I think it makes sense to use both. Use external restrictions to only give capabilities that the process will ever need, and within the process drop capabilities when they are no longer needed.
Compared to not using AppArmor, or compared to using AppArmor? The situation I'm concerned about is having an opt-in profile. (NB I don't understand how AppArmor works—linux security profiles are super confusing.)