/snap/core20/2922/usr/sbin
NameSizeModeActions
aa-remove-unknown30680755editdlrm
aa-status88390755editdlrm
aa-teardown1390755editdlrm
add-shell8600755editdlrm
addgroup377850755editdlrm
adduser377850755editdlrm
agetty690000755editdlrm
apparmor_parser15263680755editdlrm
apparmor_status88390755editdlrm
arpd801440755editdlrm
arptables2204880755editdlrm
arptables-nft2204880755editdlrm
arptables-nft-restore2204880755editdlrm
arptables-nft-save2204880755editdlrm
arptables-restore2204880755editdlrm
arptables-save2204880755editdlrm
badblocks351440755editdlrm
blkdeactivate148370755editdlrm
blkdiscard350480755editdlrm
blkid1210960755editdlrm
blkzone719120755editdlrm
blockdev678160755editdlrm
bridge1047600755editdlrm
capsh310320755editdlrm
cfdisk1050480755editdlrm
chcpu473360755editdlrm
chgpasswd677920755editdlrm
chmem637200755editdlrm
chpasswd596000755editdlrm
chroot433520755editdlrm
cpgr617840755editdlrm
cppw617840755editdlrm
cryptdisks_start15440755editdlrm
cryptdisks_stop8440755editdlrm
cryptsetup1387920755editdlrm
cryptsetup-reencrypt1078480755editdlrm
ctrlaltdel391440755editdlrm
debugfs2312240755editdlrm
delgroup164950755editdlrm
deluser164950755editdlrm
depmod1744240755editdlrm
devlink1540800755editdlrm
dhclient5212000755editdlrm
dhclient-script163040755editdlrm
dmsetup1751280755editdlrm
dmstats1751280755editdlrm
dosfsck594720755editdlrm
dosfslabel553760755editdlrm
dumpe2fs311120755editdlrm
e2freefrag188160755editdlrm
e2fsck3350640755editdlrm
e2image434000755editdlrm
e2label1091120755editdlrm
e2mmpstatus311120755editdlrm
e2scrub72960755editdlrm
e2scrub_all53950755editdlrm
e2undo229120755editdlrm
e4crypt311040755editdlrm
e4defrag351280755editdlrm
ebtables2204880755editdlrm
ebtables-nft2204880755editdlrm
ebtables-nft-restore2204880755editdlrm
ebtables-nft-save2204880755editdlrm
ebtables-restore2204880755editdlrm
ebtables-save2204880755editdlrm
faillock144880755editdlrm
fatlabel553760755editdlrm
fdformat350480755editdlrm
fdisk1538800755editdlrm
filefrag187680755editdlrm
findfs145680755editdlrm
fsck555760755editdlrm
fsck.cramfs391760755editdlrm
fsck.ext23350640755editdlrm
fsck.ext33350640755editdlrm
fsck.ext43350640755editdlrm
fsck.fat594720755editdlrm
fsck.minix1251840755editdlrm
fsck.msdos594720755editdlrm
fsck.vfat594720755editdlrm
fsfreeze145680755editdlrm
fstab-decode146480755editdlrm
fstrim719120755editdlrm
genl842640755editdlrm
getcap146480755editdlrm
getpcaps146480755editdlrm
getty690000755editdlrm
groupadd931360755editdlrm
groupdel888480755editdlrm
groupmems637360755editdlrm
groupmod971360755editdlrm
grpck636720755editdlrm
grpconv594480755editdlrm
grpunconv594480755editdlrm
halt9965840755editdlrm
hwclock1048080755editdlrm
iconvconfig311280755editdlrm
init16202240755editdlrm
insmod1744240755editdlrm
installkernel26380755editdlrm
integritysetup616720755editdlrm
invoke-rc.d170420755editdlrm
ip6119600755editdlrm
ip6tables992960755editdlrm
ip6tables-apply70570755editdlrm
ip6tables-legacy992960755editdlrm
ip6tables-legacy-restore992960755editdlrm
ip6tables-legacy-save992960755editdlrm
ip6tables-nft2204880755editdlrm
ip6tables-nft-restore2204880755editdlrm
ip6tables-nft-save2204880755editdlrm
ip6tables-restore992960755editdlrm
ip6tables-restore-translate2204880755editdlrm
ip6tables-save992960755editdlrm
ip6tables-translate2204880755editdlrm
iptables992960755editdlrm
iptables-apply70570755editdlrm
iptables-legacy992960755editdlrm
iptables-legacy-restore992960755editdlrm
iptables-legacy-save992960755editdlrm
iptables-nft2204880755editdlrm
iptables-nft-restore2204880755editdlrm
iptables-nft-save2204880755editdlrm
iptables-restore992960755editdlrm
iptables-restore-translate2204880755editdlrm
iptables-save992960755editdlrm
iptables-translate2204880755editdlrm
isosize309520755editdlrm
killall5270160755editdlrm
ldattach350480755editdlrm
ldconfig3870755editdlrm
ldconfig.real10537680755editdlrm
logsave144960755editdlrm
losetup1129920755editdlrm
lsmod1744240755editdlrm
luksformat34010755editdlrm
mkdosfs353280755editdlrm
mke2fs1378480755editdlrm
mkfs145680755editdlrm
mkfs.bfs350480755editdlrm
mkfs.cramfs431680755editdlrm
mkfs.ext21378480755editdlrm
mkfs.ext31378480755editdlrm
mkfs.ext41378480755editdlrm
mkfs.fat353280755editdlrm
mkfs.minix1087840755editdlrm
mkfs.msdos353280755editdlrm
mkfs.vfat353280755editdlrm
mkhomedir_helper227040755editdlrm
mklost+found146480755editdlrm
mkswap1087840755editdlrm
modinfo1744240755editdlrm
modprobe1744240755editdlrm
netplan7980755editdlrm
newusers1011680755editdlrm
nfnl_osf187360755editdlrm
nologin146400755editdlrm
pam-auth-update203350755editdlrm
pam_extrausers_chkpwd431682755editdlrm
pam_extrausers_update431680755editdlrm
pam_getenv28900755editdlrm
pam_tally145040755editdlrm
pam_tally2186000755editdlrm
pam_timestamp_check144880755editdlrm
pivot_root145680755editdlrm
poweroff9965840755editdlrm
pwck595680755editdlrm
pwconv553440755editdlrm
pwunconv553520755editdlrm
raw145680755editdlrm
readprofile227920755editdlrm
reboot9965840755editdlrm
remove-shell9040755editdlrm
resize2fs679680755editdlrm
rfkill514320755editdlrm
rmmod1744240755editdlrm
rmt599520755editdlrm
rmt-tar599520755editdlrm
rtacct494480755editdlrm
rtcwake473360755editdlrm
rtmon801200755editdlrm
runlevel9965840755editdlrm
runuser678160755editdlrm
service92620755editdlrm
setcap146480755editdlrm
sfdisk1415440755editdlrm
shadowconfig8850755editdlrm
shutdown9965840755editdlrm
sshd8845200755editdlrm
start-stop-daemon484560755editdlrm
sulogin514320755editdlrm
swaplabel186640755editdlrm
swapoff227600755editdlrm
swapon514320755editdlrm
switch_root145680755editdlrm
sysctl309600755editdlrm
tarcat9360755editdlrm
tc5421600755editdlrm
telinit9965840755editdlrm
tipc1292640755editdlrm
tune2fs1091120755editdlrm
tzconfig1060755editdlrm
unix_chkpwd431602755editdlrm
unix_update431600755editdlrm
update-ca-certificates54180755editdlrm
update-mime94020755editdlrm
update-passwd353920755editdlrm
update-rc.d171610755editdlrm
useradd1471600755editdlrm
userdel1012640755editdlrm
usermod1428400755editdlrm
veritysetup530640755editdlrm
vigr702000755editdlrm
vipw702000755editdlrm
visudo2234320755editdlrm
wipefs473360755editdlrm
wpa_action17350755editdlrm
wpa_cli1558720755editdlrm
wpa_supplicant29013280755editdlrm
xtables-legacy-multi992960755editdlrm
xtables-monitor2204880755editdlrm
xtables-nft-multi2204880755editdlrm
zic637840755editdlrm
zramctl1170880755editdlrm
Edit: /snap/core20/2922/usr/sbin/aa-status (8839B)
#! /usr/bin/python3 # ------------------------------------------------------------------ # # Copyright (C) 2005-2006 Novell/SUSE # Copyright (C) 2011 Canonical Ltd. # # This program is free software; you can redistribute it and/or # modify it under the terms of version 2 of the GNU General Public # License published by the Free Software Foundation. # # ------------------------------------------------------------------ import re, os, sys, errno, json # PLEASE NOTE: we try to keep aa-status as minimal as possible, for # environments where installing all of the python utils and python # apparmor module may not make sense. Please think carefully before # importing anything from apparmor; see how the apparmor.fail import is # handled below. # setup exception handling try: from apparmor.fail import enable_aa_exception_handler enable_aa_exception_handler() except ImportError: # just let normal python exceptions happen (LP: #1480492) pass def cmd_enabled(): '''Returns error code if AppArmor is not enabled''' if get_profiles() == {}: sys.exit(2) def cmd_profiled(): '''Prints the number of loaded profiles''' profiles = get_profiles() sys.stdout.write("%d\n" % len(profiles)) if profiles == {}: sys.exit(2) def cmd_enforced(): '''Prints the number of loaded enforcing profiles''' profiles = get_profiles() sys.stdout.write("%d\n" % len(filter_profiles(profiles, 'enforce'))) if profiles == {}: sys.exit(2) def cmd_complaining(): '''Prints the number of loaded non-enforcing profiles''' profiles = get_profiles() sys.stdout.write("%d\n" % len(filter_profiles(profiles, 'complain'))) if profiles == {}: sys.exit(2) def cmd_verbose(): '''Displays multiple data points about loaded profile set''' global verbose verbose = True profiles = get_profiles() processes = get_processes(profiles) stdmsg("%d profiles are loaded." % len(profiles)) for status in ('enforce', 'complain'): filtered_profiles = filter_profiles(profiles, status) stdmsg("%d profiles are in %s mode." % (len(filtered_profiles), status)) for item in filtered_profiles: stdmsg(" %s" % item) stdmsg("%d processes have profiles defined." % len(processes)) for status in ('enforce', 'complain', 'unconfined'): filtered_processes = filter_processes(processes, status) if status == 'unconfined': stdmsg("%d processes are unconfined but have a profile defined." % len(filtered_processes)) else: stdmsg("%d processes are in %s mode." % (len(filtered_processes), status)) # Sort by name, and then by pid filtered_processes.sort(key=lambda x: int(x[0])) filtered_processes.sort(key=lambda x: x[1]) for (pid, profile, exe) in filtered_processes: if exe == profile: profile = "" stdmsg(" %s (%s) %s" % (exe, pid, profile)) if profiles == {}: sys.exit(2) def cmd_json(pretty_output=False): '''Outputs multiple data points about loaded profile set in a machine-readable JSON format''' global verbose profiles = get_profiles() processes = get_processes(profiles) i = { 'version': '1', 'profiles': {}, 'processes': {} } for status in ('enforce', 'complain'): filtered_profiles = filter_profiles(profiles, status) for item in filtered_profiles: i['profiles'][item] = status for status in ('enforce', 'complain', 'unconfined'): filtered_processes = filter_processes(processes, status) for (pid, profile, exe) in filtered_processes: if exe not in i['processes']: i['processes'][exe] = [] i['processes'][exe].append({ 'profile': profile, 'pid': pid, 'status': status }) if pretty_output: sys.stdout.write(json.dumps(i, sort_keys=True, indent=4, separators=(',', ': '))) else: sys.stdout.write(json.dumps(i)) def cmd_pretty_json(): cmd_json(True) def get_profiles(): '''Fetch loaded profiles''' profiles = {} if os.path.exists("/sys/module/apparmor"): stdmsg("apparmor module is loaded.") else: errormsg("apparmor module is not loaded.") sys.exit(1) apparmorfs = find_apparmorfs() if not apparmorfs: errormsg("apparmor filesystem is not mounted.") sys.exit(3) apparmor_profiles = os.path.join(apparmorfs, "profiles") try: f = open(apparmor_profiles) except IOError as e: if e.errno == errno.EACCES: errormsg("You do not have enough privilege to read the profile set.") else: errormsg("Could not open %s: %s" % (apparmor_profiles, os.strerror(e.errno))) sys.exit(4) for p in f.readlines(): match = re.search("^([^\(]+)\s+\((\w+)\)$", p) profiles[match.group(1)] = match.group(2) f.close() return profiles def get_processes(profiles): '''Fetch process list''' processes = {} contents = os.listdir("/proc") for filename in contents: if filename.isdigit(): try: for p in open("/proc/%s/attr/current" % filename).readlines(): match = re.search("^([^\(]+)\s+\((\w+)\)$", p) exe = os.path.realpath("/proc/%s/exe" % filename) if match: processes[filename] = { 'profile' : match.group(1), \ 'exe': exe, \ 'mode' : match.group(2) } elif exe in profiles: # keep only unconfined processes that have a profile defined processes[filename] = { 'profile' : exe, \ 'exe': exe, \ 'mode' : 'unconfined' } except: pass return processes def filter_profiles(profiles, status): '''Return a list of profiles that have a particular status''' filtered = [] for key, value in list(profiles.items()): if value == status: filtered.append(key) filtered.sort() return filtered def filter_processes(processes, status): '''Return a list of processes that have a particular status''' filtered = [] for key, value in list(processes.items()): if value['mode'] == status: filtered.append([key, value['profile'], value['exe']]) return filtered def find_apparmorfs(): '''Finds AppArmor mount point''' for p in open("/proc/mounts","rb").readlines(): if p.split()[2].decode() == "securityfs" and \ os.path.exists(os.path.join(p.split()[1].decode(), "apparmor")): return os.path.join(p.split()[1].decode(), "apparmor") return False def errormsg(message): '''Prints to stderr if verbose mode is on''' global verbose if verbose: sys.stderr.write(message + "\n") def stdmsg(message): '''Prints to stdout if verbose mode is on''' global verbose if verbose: sys.stdout.write(message + "\n") def print_usage(): '''Print usage information''' sys.stdout.write('''Usage: %s [OPTIONS] Displays various information about the currently loaded AppArmor policy. OPTIONS (one only): --enabled returns error code if AppArmor not enabled --profiled prints the number of loaded policies --enforced prints the number of loaded enforcing policies --complaining prints the number of loaded non-enforcing policies --json displays multiple data points in machine-readable JSON format --pretty-json same data as --json, formatted for human consumption as well --verbose (default) displays multiple data points about loaded policy set --help this message ''' % sys.argv[0]) # Main global verbose verbose = False if len(sys.argv) > 2: sys.stderr.write("Error: Too many options.\n") print_usage() sys.exit(1) elif len(sys.argv) == 2: cmd = sys.argv.pop(1) else: cmd = '--verbose' # Command dispatch: commands = { '--enabled' : cmd_enabled, '--profiled' : cmd_profiled, '--enforced' : cmd_enforced, '--complaining' : cmd_complaining, '--json' : cmd_json, '--pretty-json' : cmd_pretty_json, '--verbose' : cmd_verbose, '-v' : cmd_verbose, '--help' : print_usage, '-h' : print_usage } if cmd in commands: commands[cmd]() sys.exit(0) else: sys.stderr.write("Error: Invalid command.\n") print_usage() sys.exit(1)