/
snap
/
snapd
/
27738
/
usr
/
lib
/
snapd
/
apparmor.d
/
abstractions
/
/snap/snapd/27738/usr/lib/snapd/apparmor.d/abstractions
mkdir
upload
Name
Size
Mode
Actions
apparmor_api/
-
0775
rm
ubuntu-browsers.d/
-
0775
rm
apache2-common
1119
0664
edit
dl
rm
aspell
412
0664
edit
dl
rm
audio
2063
0664
edit
dl
rm
authd
145
0664
edit
dl
rm
authentication
2194
0664
edit
dl
rm
base
7151
0664
edit
dl
rm
bash
1614
0664
edit
dl
rm
consoles
903
0664
edit
dl
rm
crypto
992
0664
edit
dl
rm
cups-client
820
0664
edit
dl
rm
dbus
694
0664
edit
dl
rm
dbus-accessibility
745
0664
edit
dl
rm
dbus-accessibility-strict
760
0664
edit
dl
rm
dbus-network-manager-strict
1403
0664
edit
dl
rm
dbus-session
747
0664
edit
dl
rm
dbus-session-strict
1261
0664
edit
dl
rm
dbus-strict
781
0664
edit
dl
rm
dconf
442
0664
edit
dl
rm
devices-usb
652
0664
edit
dl
rm
devices-usb-read
1014
0664
edit
dl
rm
dovecot-common
796
0664
edit
dl
rm
dri-common
542
0664
edit
dl
rm
dri-enumerate
402
0664
edit
dl
rm
enchant
2220
0664
edit
dl
rm
exo-open
1921
0664
edit
dl
rm
fcitx
558
0664
edit
dl
rm
fcitx-strict
1246
0664
edit
dl
rm
fonts
2280
0664
edit
dl
rm
freedesktop.org
1427
0664
edit
dl
rm
gio-open
1546
0664
edit
dl
rm
gnome
3772
0664
edit
dl
rm
gnupg
459
0664
edit
dl
rm
golang
310
0664
edit
dl
rm
groff
1908
0664
edit
dl
rm
gtk
1722
0664
edit
dl
rm
gvfs-open
1180
0664
edit
dl
rm
hosts_access
511
0664
edit
dl
rm
ibus
750
0664
edit
dl
rm
kde
3329
0664
edit
dl
rm
kde-globals-write
413
0664
edit
dl
rm
kde-icon-cache-write
256
0664
edit
dl
rm
kde-language-write
575
0664
edit
dl
rm
kde-open5
3666
0664
edit
dl
rm
kerberosclient
1623
0664
edit
dl
rm
ldapclient
856
0664
edit
dl
rm
libpam-systemd
770
0664
edit
dl
rm
likewise
595
0664
edit
dl
rm
mdns
554
0664
edit
dl
rm
mesa
2049
0664
edit
dl
rm
mir
694
0664
edit
dl
rm
mozc
573
0664
edit
dl
rm
mysql
739
0664
edit
dl
rm
nameservice
3342
0664
edit
dl
rm
nameservice-strict
1181
0664
edit
dl
rm
nis
625
0664
edit
dl
rm
nss-systemd
1403
0664
edit
dl
rm
nvidia
1113
0664
edit
dl
rm
opencl
370
0664
edit
dl
rm
opencl-common
516
0664
edit
dl
rm
opencl-intel
673
0664
edit
dl
rm
opencl-mesa
636
0664
edit
dl
rm
opencl-nvidia
896
0664
edit
dl
rm
opencl-pocl
2916
0664
edit
dl
rm
opengl
477
0664
edit
dl
rm
openssl
642
0664
edit
dl
rm
orbit2
197
0664
edit
dl
rm
p11-kit
999
0664
edit
dl
rm
perl
974
0664
edit
dl
rm
php
1184
0664
edit
dl
rm
php-worker
558
0664
edit
dl
rm
php5
208
0664
edit
dl
rm
postfix-common
1356
0664
edit
dl
rm
private-files
1660
0664
edit
dl
rm
private-files-strict
1212
0664
edit
dl
rm
python
2497
0664
edit
dl
rm
qt5
863
0664
edit
dl
rm
qt5-compose-cache-write
399
0664
edit
dl
rm
qt5-settings-write
514
0664
edit
dl
rm
qt6
863
0664
edit
dl
rm
qt6-compose-cache-write
399
0664
edit
dl
rm
qt6-settings-write
515
0664
edit
dl
rm
recent-documents-write
466
0664
edit
dl
rm
ruby
1008
0664
edit
dl
rm
samba
1299
0664
edit
dl
rm
samba-rpcd
817
0664
edit
dl
rm
smbpass
581
0664
edit
dl
rm
snap_browsers
1579
0664
edit
dl
rm
ssl_certs
1522
0664
edit
dl
rm
ssl_keys
938
0664
edit
dl
rm
svn-repositories
1759
0664
edit
dl
rm
terminfo
296
0664
edit
dl
rm
transmission-common
4379
0664
edit
dl
rm
trash
3621
0664
edit
dl
rm
ubuntu-bittorrent-clients
821
0664
edit
dl
rm
ubuntu-browsers
1621
0664
edit
dl
rm
ubuntu-console-browsers
731
0664
edit
dl
rm
ubuntu-console-email
718
0664
edit
dl
rm
ubuntu-email
1087
0664
edit
dl
rm
ubuntu-feed-readers
456
0664
edit
dl
rm
ubuntu-gnome-terminal
300
0664
edit
dl
rm
ubuntu-helpers
4019
0664
edit
dl
rm
ubuntu-konsole
453
0664
edit
dl
rm
ubuntu-media-players
2352
0664
edit
dl
rm
ubuntu-unity7-base
2558
0664
edit
dl
rm
ubuntu-unity7-launcher
311
0664
edit
dl
rm
ubuntu-unity7-messaging
313
0664
edit
dl
rm
ubuntu-xterm
346
0664
edit
dl
rm
user-download
987
0664
edit
dl
rm
user-mail
944
0664
edit
dl
rm
user-manpages
1000
0664
edit
dl
rm
user-tmp
760
0664
edit
dl
rm
user-write
972
0664
edit
dl
rm
video
596
0664
edit
dl
rm
vulkan
624
0664
edit
dl
rm
wayland
713
0664
edit
dl
rm
web-data
811
0664
edit
dl
rm
winbind
882
0664
edit
dl
rm
wutmp
942
0664
edit
dl
rm
X
2061
0664
edit
dl
rm
xad
984
0664
edit
dl
rm
xdg-desktop
782
0664
edit
dl
rm
xdg-open
2286
0664
edit
dl
rm
Edit:
/snap/snapd/27738/usr/lib/snapd/apparmor.d/abstractions/base
(7151B)
# vim:syntax=apparmor # ------------------------------------------------------------------ # # Copyright (C) 2002-2009 Novell/SUSE # Copyright (C) 2009-2011 Canonical Ltd. # # This program is free software; you can redistribute it and/or # modify it under the terms of version 2 of the GNU General Public # License published by the Free Software Foundation. # # ------------------------------------------------------------------ abi <abi/4.0>, include <abstractions/crypto> # (Note that the ldd profile has inlined this file; if you make # modifications here, please consider including them in the ldd # profile as well.) # The __canary_death_handler function writes a time-stamped log # message to /dev/log for logging by syslogd. So, /dev/log, timezones, # and localisations of date should be available EVERYWHERE, so # StackGuard, FormatGuard, etc., alerts can be properly logged. /dev/log w, /dev/random r, /dev/urandom r, # Allow access to the uuidd daemon (this daemon is a thin wrapper around # time and getrandom()/{,u}random and, when available, runs under an # unprivilged, dedicated user). @{run}/uuidd/request rw, @{etc_ro}/locale/** r, @{etc_ro}/locale.alias r, @{etc_ro}/localtime r, @{etc_rw}/localtime r, /usr/share/locale-bundle/** r, /usr/share/locale-langpack/** r, /usr/share/locale/ r, /usr/share/locale/** r, /usr/share/**/locale/** r, /usr/share/zoneinfo{,-icu}/ r, /usr/share/zoneinfo{,-icu}/** r, /usr/share/X11/locale/** r, @{run}/systemd/journal/dev-log w, # systemd native journal API (see sd_journal_print(4)) @{run}/systemd/journal/socket w, # Nested containers and anything using systemd-cat need this. 'r' shouldn't # be required but applications fail without it. journald doesn't leak # anything when reading so this is ok. @{run}/systemd/journal/stdout rw, /usr/lib{,32,64}/locale/** mr, /usr/lib{,32,64}/gconv/*.so mr, /usr/lib{,32,64}/gconv/gconv-modules* mr, /usr/lib/@{multiarch}/gconv/*.so mr, /usr/lib/@{multiarch}/gconv/gconv-modules* mr, # used by glibc when binding to ephemeral ports @{etc_ro}/bindresvport.blacklist r, # ld.so.cache and ld are used to load shared libraries; they are best # available everywhere @{etc_ro}/ld.so.cache mr, @{etc_ro}/ld.so.conf r, @{etc_ro}/ld.so.conf.d/{,*.conf} r, @{etc_ro}/ld.so.preload r, @{etc_ro}/ld-musl-*.path r, /{usr/,}lib{,32,64}/ld{,32,64}-*.so mr, /{usr/,}lib/@{multiarch}/ld{,32,64}-*.so mr, /{usr/,}lib/tls/i686/{cmov,nosegneg}/ld-*.so mr, /{usr/,}lib/i386-linux-gnu/tls/i686/{cmov,nosegneg}/ld-*.so mr, /opt/*-linux-uclibc/lib/ld-uClibc*so* mr, # we might as well allow everything to use common libraries /{usr/,}lib{,32,64}/** r, /{usr/,}lib{,32,64}/**.so* mr, /{usr/,}lib/@{multiarch}/** r, /{usr/,}lib/@{multiarch}/**.so* mr, /{usr/,}lib/tls/i686/{cmov,nosegneg}/*.so* mr, /{usr/,}lib/i386-linux-gnu/tls/i686/{cmov,nosegneg}/*.so* mr, # FIPS-140-2 versions of some crypto libraries need to access their # associated integrity verification file, or they will abort. /{usr/,}lib{,32,64}/.lib*.so*.hmac r, /{usr/,}lib/@{multiarch}/.lib*.so*.hmac r, # /dev/null is pretty harmless and frequently used /dev/null rw, # as is /dev/zero /dev/zero rw, # recent glibc uses /dev/full in preference to /dev/null for programs # that don't have open fds at exec() /dev/full rw, # Sometimes used to determine kernel/user interfaces to use @{PROC}/sys/kernel/version r, # Depending on which glibc routine uses this file, base may not be the # best place -- but many profiles require it, and it is quite harmless. @{PROC}/sys/kernel/ngroups_max r, # Used to determine if Linux is running in FIPS mode @{PROC}/sys/crypto/fips_enabled r, # glibc's sysconf(3) routine to determine free memory, etc @{PROC}/meminfo r, @{PROC}/stat r, @{PROC}/cpuinfo r, @{sys}/devices/system/cpu/ r, @{sys}/devices/system/cpu/online r, @{sys}/devices/system/cpu/possible r, # transparent hugepage support @{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r, # glibc's *printf protections read the maps file @{PROC}/@{pid}/{maps,auxv,status} r, # some applications will display license information /usr/share/common-licenses/** r, # glibc statvfs @{PROC}/filesystems r, # glibc malloc (man 5 proc) @{PROC}/sys/vm/overcommit_memory r, # Allow determining the highest valid capability of the running kernel @{PROC}/sys/kernel/cap_last_cap r, # Allow other processes to read our /proc entries, futexes, perf tracing and # kcmp for now (they will need 'read' in the first place). Administrators can # override with: # deny ptrace (readby) ... ptrace (readby), # Allow other processes to trace us by default (they will need 'trace' in # the first place). Administrators can override with: # deny ptrace (tracedby) ... ptrace (tracedby), # Allow us to ptrace read ourselves ptrace (read) peer=@{profile_name}, # Allow unconfined processes to send us signals by default signal (receive) peer=unconfined, # Allow us to signal ourselves signal peer=@{profile_name}, # Checking for PID existence is quite common so add it by default for now signal (receive, send) set=("exists"), # Allow us to create and use abstract and anonymous sockets unix peer=(label=@{profile_name}), # Allow unconfined processes to us via unix sockets unix (receive) peer=(label=unconfined), # Allow us to create abstract and anonymous sockets unix (create), # Allow us to getattr, getopt, setop and shutdown on unix sockets unix (getattr, getopt, setopt, shutdown), # Workaround https://launchpad.net/bugs/359338 until upstream handles stacked # filesystems generally. This does not appreciably decrease security with # Ubuntu profiles because the user is expected to have access to files owned # by him/her. Exceptions to this are explicit in the profiles. While this rule # grants access to those exceptions, the intended privacy is maintained due to # the encrypted contents of the files in this directory. Files in this # directory will also use filename encryption by default, so the files are # further protected. Also, with the use of 'owner', this rule properly # prevents access to the files from processes running under a different uid. # encrypted ~/.Private and old-style encrypted $HOME owner @{HOME}/.Private/ r, owner @{HOME}/.Private/** mrixwlk, # new-style encrypted $HOME owner @{HOMEDIRS}/.ecryptfs/*/.Private/ r, owner @{HOMEDIRS}/.ecryptfs/*/.Private/** mrixwlk, # Include additions to the abstraction include if exists <abstractions/base.d>
Save
cmd:
run