mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2025-01-30 14:55:15 +01:00
210 lines
7.4 KiB
Text
210 lines
7.4 KiB
Text
# apparmor.d - Full set of apparmor profiles
|
|
# Copyright (C) 2019-2022 Mikhail Morfikov
|
|
# Copyright (C) 2022 Alexandre Pujol <alexandre@pujol.io>
|
|
# Copyright (C) 2022 Jeroen Rijken
|
|
# SPDX-License-Identifier: GPL-2.0-only
|
|
|
|
abi <abi/3.0>,
|
|
|
|
include <tunables/global>
|
|
|
|
@{exec_path} = /{usr/,}bin/run-parts
|
|
profile run-parts @{exec_path} {
|
|
include <abstractions/base>
|
|
include <abstractions/consoles>
|
|
|
|
@{exec_path} mr,
|
|
|
|
/usr/share/update-notifier/notify-reboot-required rPx,
|
|
/usr/share/update-notifier/notify-updates-outdated rPx,
|
|
|
|
# Crontrab
|
|
/etc/cron.{hourly,daily,weekly,monthly}/ r,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/0anacron rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/apport rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/apt-compat rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/apt-listbugs rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/apt-show-versions rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/apt-xapian-index rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/aptitude rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/bsdmainutils rPUx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/checksecurity rPUx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/cracklib-runtime rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/debsums rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/debtags rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/dlocate rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/dpkg rPUx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/etckeeper rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/exim4-base rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/logrotate rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/man-db rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/mlocate rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/passwd rPUx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/plocate rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/popularity-contest rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/spamassassin rPUx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/sysstat rPx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/tor rPUx,
|
|
/etc/cron.{hourly,daily,weekly,monthly}/vrms rPUx,
|
|
|
|
# Network
|
|
/etc/network/if-down.d/ r,
|
|
/etc/network/if-down.d/openvpn rPUx,
|
|
/etc/network/if-down.d/resolvconf rPUx,
|
|
/etc/network/if-down.d/wpasupplicant rPUx,
|
|
|
|
/etc/hostapd/ifupdown.sh rPUx,
|
|
/etc/macchanger/ifupdown.sh rPUx,
|
|
/etc/wpa_supplicant/ifupdown.sh rPUx,
|
|
|
|
/etc/network/if-post-down.d/ r,
|
|
/etc/network/if-post-down.d/bridge rPUx,
|
|
/etc/network/if-post-down.d/chrony rPUx,
|
|
/etc/network/if-post-down.d/hostapd rPUx,
|
|
/etc/network/if-post-down.d/ifenslave rPUx,
|
|
/etc/network/if-post-down.d/macchanger rPUx,
|
|
/etc/network/if-post-down.d/wireless-tools rPUx,
|
|
/etc/network/if-post-down.d/wpasupplicant rPUx,
|
|
|
|
/etc/network/if-pre-up.d/ r,
|
|
/etc/network/if-pre-up.d/bridge rPUx,
|
|
/etc/network/if-pre-up.d/ethtool rPUx,
|
|
/etc/network/if-pre-up.d/hostapd rPUx,
|
|
/etc/network/if-pre-up.d/ifenslave rPUx,
|
|
/etc/network/if-pre-up.d/macchanger rPUx,
|
|
/etc/network/if-pre-up.d/random-secret rPUx,
|
|
/etc/network/if-pre-up.d/wireless-tools rPUx,
|
|
/etc/network/if-pre-up.d/wpasupplicant rPUx,
|
|
|
|
/etc/network/if-up.d/ r,
|
|
/etc/network/if-up.d/*resolvconf rPUx,
|
|
/etc/network/if-up.d/avahi-autoipd rPUx,
|
|
/etc/network/if-up.d/chrony rPUx,
|
|
/etc/network/if-up.d/ethtool rPUx,
|
|
/etc/network/if-up.d/ifenslave rPUx,
|
|
/etc/network/if-up.d/openvpn rPUx,
|
|
/etc/network/if-up.d/postfix rPUx,
|
|
/etc/network/if-up.d/ubuntu-fan rPx,
|
|
/etc/network/if-up.d/wpasupplicant rPUx,
|
|
|
|
# Motd
|
|
/etc/update-motd.d/ r,
|
|
/etc/update-motd.d/[0-9]*-[a-z]* rCx -> motd,
|
|
|
|
# Kernel
|
|
/etc/kernel/header_postinst.d/ r,
|
|
/etc/kernel/header_postinst.d/dkms rCx -> kernel,
|
|
|
|
/etc/kernel/postinst.d/ r,
|
|
/etc/kernel/postinst.d/apt-auto-removal rCx -> kernel,
|
|
/etc/kernel/postinst.d/dkms rCx -> kernel,
|
|
/etc/kernel/postinst.d/initramfs-tools rCx -> kernel,
|
|
/etc/kernel/postinst.d/unattended-upgrades rCx -> kernel,
|
|
/etc/kernel/postinst.d/zz-update-grub rCx -> kernel,
|
|
/etc/kernel/postinst.d/xx-update-initrd-links rCx -> kernel,
|
|
|
|
/etc/kernel/postrm.d/ r,
|
|
/etc/kernel/postrm.d/initramfs-tools rCx -> kernel,
|
|
/etc/kernel/postrm.d/zz-update-grub rCx -> kernel,
|
|
|
|
/etc/kernel/preinst.d/ r,
|
|
/etc/kernel/preinst.d/intel-microcode rCx -> kernel,
|
|
|
|
/etc/kernel/prerm.d/ r,
|
|
/etc/kernel/prerm.d/dkms rCx -> kernel,
|
|
|
|
owner /tmp/#[0-9]*[0-9] rw,
|
|
owner /tmp/file* rw,
|
|
|
|
profile motd {
|
|
include <abstractions/base>
|
|
|
|
/{usr/,}bin/{,ba,da}sh rix,
|
|
/{usr/,}bin/{e,}grep rix,
|
|
/{usr/,}bin/cat rix,
|
|
/{usr/,}bin/cut rix,
|
|
/{usr/,}bin/find rix,
|
|
/{usr/,}bin/head rix,
|
|
/{usr/,}bin/id rix,
|
|
/{usr/,}bin/sort rix,
|
|
/{usr/,}bin/tr rix,
|
|
/{usr/,}bin/uname rix,
|
|
|
|
/{usr/,}lib/ubuntu-release-upgrader/release-upgrade-motd rPx,
|
|
/{usr/,}lib/update-notifier/update-motd-fsck-at-reboot rPx,
|
|
/{usr/,}lib/update-notifier/update-motd-reboot-required rix,
|
|
/usr/share/unattended-upgrades/update-motd-unattended-upgrades rix,
|
|
/usr/share/update-notifier/notify-updates-outdated rPx,
|
|
|
|
/ r,
|
|
/etc/default/motd-news r,
|
|
/etc/lsb-release r,
|
|
/etc/update-motd.d/[0-9]*-[a-z]* r,
|
|
|
|
/var/cache/motd-news r,
|
|
/var/lib/update-notifier/updates-available r,
|
|
|
|
@{run}/motd.d/{,*} r,
|
|
|
|
@{PROC}/@{pids}/mounts r,
|
|
|
|
}
|
|
|
|
profile kernel {
|
|
include <abstractions/base>
|
|
include <abstractions/consoles>
|
|
include <abstractions/nameservice-strict>
|
|
|
|
capability sys_module,
|
|
|
|
/{usr/,}bin/{,ba,da}sh rix,
|
|
/{usr/,}bin/{,e}grep rix,
|
|
/{usr/,}bin/cat rix,
|
|
/{usr/,}bin/chmod rix,
|
|
/{usr/,}bin/cut rix,
|
|
/{usr/,}bin/dirname rix,
|
|
/{usr/,}bin/{,m,g}awk rix,
|
|
/{usr/,}bin/kmod rix,
|
|
/{usr/,}bin/mv rix,
|
|
/{usr/,}bin/rm rix,
|
|
/{usr/,}bin/rmdir rix,
|
|
/{usr/,}bin/sed rix,
|
|
/{usr/,}bin/sort rix,
|
|
/{usr/,}bin/touch rix,
|
|
/{usr/,}bin/tr rix,
|
|
/{usr/,}bin/uname rix,
|
|
/{usr/,}bin/which{,.debianutils} rix,
|
|
|
|
/{usr/,}{s,}bin/dkms rPx,
|
|
/{usr/,}{s,}bin/update-grub rPUx,
|
|
/{usr/,}{s,}bin/update-initramfs rPx,
|
|
/{usr/,}bin/apt-config rPx,
|
|
/{usr/,}bin/dpkg rPx -> child-dpkg,
|
|
/{usr/,}bin/systemd-detect-virt rPx,
|
|
/{usr/,}lib/dkms/dkms_autoinstaller rPx,
|
|
|
|
/{usr/,}lib/modules/*/updates/ w,
|
|
/{usr/,}lib/modules/*/updates/dkms/ w,
|
|
|
|
/etc/kernel/header_postinst.d/* r,
|
|
/etc/kernel/{postinst,postrm,preinst,prerm}.d/* r,
|
|
|
|
# For shell pwd
|
|
/ r,
|
|
/boot/ r,
|
|
|
|
/etc/apt/apt.conf.d/ r,
|
|
/etc/apt/apt.conf.d/01autoremove-kernels{,.dpkg-new} rw,
|
|
/etc/modprobe.d/ r,
|
|
/etc/modprobe.d/*.conf r,
|
|
|
|
@{run}/reboot-required w,
|
|
@{run}/reboot-required.pkgs rw,
|
|
|
|
@{PROC}/devices r,
|
|
@{PROC}/cmdline r,
|
|
|
|
}
|
|
|
|
include if exists <local/run-parts>
|
|
}
|