/
etc
/
apparmor.d
/
abstractions
/
/etc/apparmor.d/abstractions
mkdir
upload
Name
Size
Mode
Actions
apparmor_api/
-
0755
rm
ubuntu-browsers.d/
-
0755
rm
apache2-common
1119
0644
edit
dl
rm
aspell
412
0644
edit
dl
rm
audio
2063
0644
edit
dl
rm
authentication
2194
0644
edit
dl
rm
base
7093
0644
edit
dl
rm
bash
1614
0644
edit
dl
rm
consoles
903
0644
edit
dl
rm
crypto
992
0644
edit
dl
rm
cups-client
820
0644
edit
dl
rm
dbus
694
0644
edit
dl
rm
dbus-accessibility
745
0644
edit
dl
rm
dbus-accessibility-strict
760
0644
edit
dl
rm
dbus-network-manager-strict
1403
0644
edit
dl
rm
dbus-session
747
0644
edit
dl
rm
dbus-session-strict
1261
0644
edit
dl
rm
dbus-strict
781
0644
edit
dl
rm
dconf
344
0644
edit
dl
rm
dovecot-common
675
0644
edit
dl
rm
dri-common
542
0644
edit
dl
rm
dri-enumerate
393
0644
edit
dl
rm
enchant
2220
0644
edit
dl
rm
exo-open
1921
0644
edit
dl
rm
fcitx
558
0644
edit
dl
rm
fcitx-strict
821
0644
edit
dl
rm
fonts
2280
0644
edit
dl
rm
freedesktop.org
1684
0644
edit
dl
rm
gio-open
1546
0644
edit
dl
rm
gnome
3815
0644
edit
dl
rm
gnupg
459
0644
edit
dl
rm
groff
1908
0644
edit
dl
rm
gtk
1622
0644
edit
dl
rm
gvfs-open
1180
0644
edit
dl
rm
hosts_access
511
0644
edit
dl
rm
ibus
992
0644
edit
dl
rm
kde
3329
0644
edit
dl
rm
kde-globals-write
413
0644
edit
dl
rm
kde-icon-cache-write
256
0644
edit
dl
rm
kde-language-write
575
0644
edit
dl
rm
kde-open5
3666
0644
edit
dl
rm
kerberosclient
1476
0644
edit
dl
rm
ldapclient
856
0644
edit
dl
rm
libpam-systemd
770
0644
edit
dl
rm
likewise
595
0644
edit
dl
rm
mdns
554
0644
edit
dl
rm
mesa
1239
0644
edit
dl
rm
mir
694
0644
edit
dl
rm
mozc
573
0644
edit
dl
rm
mysql
739
0644
edit
dl
rm
nameservice
4563
0644
edit
dl
rm
nis
625
0644
edit
dl
rm
nss-systemd
1248
0644
edit
dl
rm
nvidia
1113
0644
edit
dl
rm
opencl
370
0644
edit
dl
rm
opencl-common
516
0644
edit
dl
rm
opencl-intel
673
0644
edit
dl
rm
opencl-mesa
636
0644
edit
dl
rm
opencl-nvidia
896
0644
edit
dl
rm
opencl-pocl
2916
0644
edit
dl
rm
openssl
642
0644
edit
dl
rm
orbit2
197
0644
edit
dl
rm
p11-kit
999
0644
edit
dl
rm
perl
974
0644
edit
dl
rm
php
1128
0644
edit
dl
rm
php-worker
558
0644
edit
dl
rm
php5
208
0644
edit
dl
rm
postfix-common
1356
0644
edit
dl
rm
private-files
1660
0644
edit
dl
rm
private-files-strict
1212
0644
edit
dl
rm
python
2293
0644
edit
dl
rm
qt5
863
0644
edit
dl
rm
qt5-compose-cache-write
399
0644
edit
dl
rm
qt5-settings-write
514
0644
edit
dl
rm
recent-documents-write
466
0644
edit
dl
rm
ruby
1008
0644
edit
dl
rm
samba
1299
0644
edit
dl
rm
samba-rpcd
817
0644
edit
dl
rm
smbpass
581
0644
edit
dl
rm
snap_browsers
1579
0644
edit
dl
rm
ssl_certs
1522
0644
edit
dl
rm
ssl_keys
938
0644
edit
dl
rm
svn-repositories
1759
0644
edit
dl
rm
transmission-common
4379
0644
edit
dl
rm
trash
3621
0644
edit
dl
rm
ubuntu-bittorrent-clients
821
0644
edit
dl
rm
ubuntu-browsers
1621
0644
edit
dl
rm
ubuntu-console-browsers
731
0644
edit
dl
rm
ubuntu-console-email
718
0644
edit
dl
rm
ubuntu-email
1087
0644
edit
dl
rm
ubuntu-feed-readers
456
0644
edit
dl
rm
ubuntu-gnome-terminal
300
0644
edit
dl
rm
ubuntu-helpers
3909
0644
edit
dl
rm
ubuntu-konsole
453
0644
edit
dl
rm
ubuntu-media-players
2352
0644
edit
dl
rm
ubuntu-unity7-base
2558
0644
edit
dl
rm
ubuntu-unity7-launcher
311
0644
edit
dl
rm
ubuntu-unity7-messaging
313
0644
edit
dl
rm
ubuntu-xterm
346
0644
edit
dl
rm
user-download
987
0644
edit
dl
rm
user-mail
944
0644
edit
dl
rm
user-manpages
1000
0644
edit
dl
rm
user-tmp
760
0644
edit
dl
rm
user-write
972
0644
edit
dl
rm
video
596
0644
edit
dl
rm
vulkan
1133
0644
edit
dl
rm
wayland
713
0644
edit
dl
rm
web-data
811
0644
edit
dl
rm
winbind
882
0644
edit
dl
rm
wutmp
788
0644
edit
dl
rm
X
1989
0644
edit
dl
rm
xad
984
0644
edit
dl
rm
xdg-desktop
782
0644
edit
dl
rm
xdg-open
2286
0644
edit
dl
rm
Edit:
/etc/apparmor.d/abstractions/base
(7093B)
# vim:syntax=apparmor # ------------------------------------------------------------------ # # Copyright (C) 2002-2009 Novell/SUSE # Copyright (C) 2009-2011 Canonical Ltd. # # This program is free software; you can redistribute it and/or # modify it under the terms of version 2 of the GNU General Public # License published by the Free Software Foundation. # # ------------------------------------------------------------------ abi <abi/4.0>, include <abstractions/crypto> # (Note that the ldd profile has inlined this file; if you make # modifications here, please consider including them in the ldd # profile as well.) # The __canary_death_handler function writes a time-stamped log # message to /dev/log for logging by syslogd. So, /dev/log, timezones, # and localisations of date should be available EVERYWHERE, so # StackGuard, FormatGuard, etc., alerts can be properly logged. /dev/log w, /dev/random r, /dev/urandom r, # Allow access to the uuidd daemon (this daemon is a thin wrapper around # time and getrandom()/{,u}random and, when available, runs under an # unprivilged, dedicated user). @{run}/uuidd/request r, @{etc_ro}/locale/** r, @{etc_ro}/locale.alias r, @{etc_ro}/localtime r, @{etc_rw}/localtime r, /etc/writable/localtime r, /usr/share/locale-bundle/** r, /usr/share/locale-langpack/** r, /usr/share/locale/ r, /usr/share/locale/** r, /usr/share/**/locale/** r, /usr/share/zoneinfo{,-icu}/ r, /usr/share/zoneinfo{,-icu}/** r, /usr/share/X11/locale/** r, @{run}/systemd/journal/dev-log w, # systemd native journal API (see sd_journal_print(4)) @{run}/systemd/journal/socket w, # Nested containers and anything using systemd-cat need this. 'r' shouldn't # be required but applications fail without it. journald doesn't leak # anything when reading so this is ok. @{run}/systemd/journal/stdout rw, /usr/lib{,32,64}/locale/** mr, /usr/lib{,32,64}/gconv/*.so mr, /usr/lib{,32,64}/gconv/gconv-modules* mr, /usr/lib/@{multiarch}/gconv/*.so mr, /usr/lib/@{multiarch}/gconv/gconv-modules* mr, # used by glibc when binding to ephemeral ports @{etc_ro}/bindresvport.blacklist r, # ld.so.cache and ld are used to load shared libraries; they are best # available everywhere @{etc_ro}/ld.so.cache mr, @{etc_ro}/ld.so.conf r, @{etc_ro}/ld.so.conf.d/{,*.conf} r, @{etc_ro}/ld.so.preload r, @{etc_ro}/ld-musl-*.path r, /{usr/,}lib{,32,64}/ld{,32,64}-*.so mr, /{usr/,}lib/@{multiarch}/ld{,32,64}-*.so mr, /{usr/,}lib/tls/i686/{cmov,nosegneg}/ld-*.so mr, /{usr/,}lib/i386-linux-gnu/tls/i686/{cmov,nosegneg}/ld-*.so mr, /opt/*-linux-uclibc/lib/ld-uClibc*so* mr, # we might as well allow everything to use common libraries /{usr/,}lib{,32,64}/** r, /{usr/,}lib{,32,64}/**.so* mr, /{usr/,}lib/@{multiarch}/** r, /{usr/,}lib/@{multiarch}/**.so* mr, /{usr/,}lib/tls/i686/{cmov,nosegneg}/*.so* mr, /{usr/,}lib/i386-linux-gnu/tls/i686/{cmov,nosegneg}/*.so* mr, # FIPS-140-2 versions of some crypto libraries need to access their # associated integrity verification file, or they will abort. /{usr/,}lib{,32,64}/.lib*.so*.hmac r, /{usr/,}lib/@{multiarch}/.lib*.so*.hmac r, # /dev/null is pretty harmless and frequently used /dev/null rw, # as is /dev/zero /dev/zero rw, # recent glibc uses /dev/full in preference to /dev/null for programs # that don't have open fds at exec() /dev/full rw, # Sometimes used to determine kernel/user interfaces to use @{PROC}/sys/kernel/version r, # Depending on which glibc routine uses this file, base may not be the # best place -- but many profiles require it, and it is quite harmless. @{PROC}/sys/kernel/ngroups_max r, # glibc's sysconf(3) routine to determine free memory, etc @{PROC}/meminfo r, @{PROC}/stat r, @{PROC}/cpuinfo r, @{sys}/devices/system/cpu/ r, @{sys}/devices/system/cpu/online r, @{sys}/devices/system/cpu/possible r, # transparent hugepage support @{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r, # glibc's *printf protections read the maps file @{PROC}/@{pid}/{maps,auxv,status} r, # some applications will display license information /usr/share/common-licenses/** r, # glibc statvfs @{PROC}/filesystems r, # glibc malloc (man 5 proc) @{PROC}/sys/vm/overcommit_memory r, # Allow determining the highest valid capability of the running kernel @{PROC}/sys/kernel/cap_last_cap r, # Allow other processes to read our /proc entries, futexes, perf tracing and # kcmp for now (they will need 'read' in the first place). Administrators can # override with: # deny ptrace (readby) ... ptrace (readby), # Allow other processes to trace us by default (they will need 'trace' in # the first place). Administrators can override with: # deny ptrace (tracedby) ... ptrace (tracedby), # Allow us to ptrace read ourselves ptrace (read) peer=@{profile_name}, # Allow unconfined processes to send us signals by default signal (receive) peer=unconfined, # Allow us to signal ourselves signal peer=@{profile_name}, # Checking for PID existence is quite common so add it by default for now signal (receive, send) set=("exists"), # Allow us to create and use abstract and anonymous sockets unix peer=(label=@{profile_name}), # Allow unconfined processes to us via unix sockets unix (receive) peer=(label=unconfined), # Allow us to create abstract and anonymous sockets unix (create), # Allow us to getattr, getopt, setop and shutdown on unix sockets unix (getattr, getopt, setopt, shutdown), # Workaround https://launchpad.net/bugs/359338 until upstream handles stacked # filesystems generally. This does not appreciably decrease security with # Ubuntu profiles because the user is expected to have access to files owned # by him/her. Exceptions to this are explicit in the profiles. While this rule # grants access to those exceptions, the intended privacy is maintained due to # the encrypted contents of the files in this directory. Files in this # directory will also use filename encryption by default, so the files are # further protected. Also, with the use of 'owner', this rule properly # prevents access to the files from processes running under a different uid. # encrypted ~/.Private and old-style encrypted $HOME owner @{HOME}/.Private/ r, owner @{HOME}/.Private/** mrixwlk, # new-style encrypted $HOME owner @{HOMEDIRS}/.ecryptfs/*/.Private/ r, owner @{HOMEDIRS}/.ecryptfs/*/.Private/** mrixwlk, # Include additions to the abstraction include if exists <abstractions/base.d>
Save
cmd:
run