/
snap
/
core22
/
2411
/
etc
/
apparmor.d
/
abstractions
/
/snap/core22/2411/etc/apparmor.d/abstractions
mkdir
upload
Name
Size
Mode
Actions
apparmor_api/
-
0755
rm
ubuntu-browsers.d/
-
0755
rm
apache2-common
978
0644
edit
dl
rm
aspell
412
0644
edit
dl
rm
audio
1988
0644
edit
dl
rm
authentication
1857
0644
edit
dl
rm
base
6929
0644
edit
dl
rm
bash
1614
0644
edit
dl
rm
consoles
903
0644
edit
dl
rm
crypto
809
0644
edit
dl
rm
cups-client
820
0644
edit
dl
rm
dbus
694
0644
edit
dl
rm
dbus-accessibility
745
0644
edit
dl
rm
dbus-accessibility-strict
760
0644
edit
dl
rm
dbus-network-manager-strict
1403
0644
edit
dl
rm
dbus-session
747
0644
edit
dl
rm
dbus-session-strict
1010
0644
edit
dl
rm
dbus-strict
781
0644
edit
dl
rm
dconf
344
0644
edit
dl
rm
dovecot-common
675
0644
edit
dl
rm
dri-common
542
0644
edit
dl
rm
dri-enumerate
393
0644
edit
dl
rm
enchant
2220
0644
edit
dl
rm
exo-open
1921
0644
edit
dl
rm
fcitx
558
0644
edit
dl
rm
fcitx-strict
821
0644
edit
dl
rm
fonts
2278
0644
edit
dl
rm
freedesktop.org
1404
0644
edit
dl
rm
gio-open
1546
0644
edit
dl
rm
gnome
3815
0644
edit
dl
rm
gnupg
459
0644
edit
dl
rm
gtk
1458
0644
edit
dl
rm
gvfs-open
1180
0644
edit
dl
rm
hosts_access
511
0644
edit
dl
rm
ibus
992
0644
edit
dl
rm
kde
2867
0644
edit
dl
rm
kde-globals-write
413
0644
edit
dl
rm
kde-icon-cache-write
256
0644
edit
dl
rm
kde-language-write
575
0644
edit
dl
rm
kde-open5
3699
0644
edit
dl
rm
kerberosclient
1281
0644
edit
dl
rm
ldapclient
856
0644
edit
dl
rm
libpam-systemd
770
0644
edit
dl
rm
likewise
595
0644
edit
dl
rm
mdns
554
0644
edit
dl
rm
mesa
1186
0644
edit
dl
rm
mir
694
0644
edit
dl
rm
mozc
573
0644
edit
dl
rm
mysql
739
0644
edit
dl
rm
nameservice
4389
0644
edit
dl
rm
nis
625
0644
edit
dl
rm
nss-systemd
1248
0644
edit
dl
rm
nvidia
751
0644
edit
dl
rm
opencl
370
0644
edit
dl
rm
opencl-common
516
0644
edit
dl
rm
opencl-intel
673
0644
edit
dl
rm
opencl-mesa
636
0644
edit
dl
rm
opencl-nvidia
896
0644
edit
dl
rm
opencl-pocl
2916
0644
edit
dl
rm
openssl
648
0644
edit
dl
rm
orbit2
197
0644
edit
dl
rm
p11-kit
999
0644
edit
dl
rm
perl
974
0644
edit
dl
rm
php
1158
0644
edit
dl
rm
php-worker
558
0644
edit
dl
rm
php5
208
0644
edit
dl
rm
postfix-common
1356
0644
edit
dl
rm
private-files
1660
0644
edit
dl
rm
private-files-strict
1212
0644
edit
dl
rm
python
1860
0644
edit
dl
rm
qt5
863
0644
edit
dl
rm
qt5-compose-cache-write
399
0644
edit
dl
rm
qt5-settings-write
514
0644
edit
dl
rm
recent-documents-write
466
0644
edit
dl
rm
ruby
1008
0644
edit
dl
rm
samba
1159
0644
edit
dl
rm
smbpass
581
0644
edit
dl
rm
snap_browsers
1672
0644
edit
dl
rm
ssl_certs
1560
0644
edit
dl
rm
ssl_keys
938
0644
edit
dl
rm
svn-repositories
1760
0644
edit
dl
rm
ubuntu-bittorrent-clients
821
0644
edit
dl
rm
ubuntu-browsers
1621
0644
edit
dl
rm
ubuntu-console-browsers
731
0644
edit
dl
rm
ubuntu-console-email
718
0644
edit
dl
rm
ubuntu-email
1087
0644
edit
dl
rm
ubuntu-feed-readers
456
0644
edit
dl
rm
ubuntu-gnome-terminal
300
0644
edit
dl
rm
ubuntu-helpers
3791
0644
edit
dl
rm
ubuntu-konsole
453
0644
edit
dl
rm
ubuntu-media-players
2352
0644
edit
dl
rm
ubuntu-unity7-base
2558
0644
edit
dl
rm
ubuntu-unity7-launcher
311
0644
edit
dl
rm
ubuntu-unity7-messaging
313
0644
edit
dl
rm
ubuntu-xterm
346
0644
edit
dl
rm
user-download
987
0644
edit
dl
rm
user-mail
944
0644
edit
dl
rm
user-manpages
1000
0644
edit
dl
rm
user-tmp
760
0644
edit
dl
rm
user-write
972
0644
edit
dl
rm
video
231
0644
edit
dl
rm
vulkan
1089
0644
edit
dl
rm
wayland
645
0644
edit
dl
rm
web-data
811
0644
edit
dl
rm
winbind
882
0644
edit
dl
rm
wutmp
711
0644
edit
dl
rm
X
1989
0644
edit
dl
rm
xad
984
0644
edit
dl
rm
xdg-desktop
782
0644
edit
dl
rm
xdg-open
2285
0644
edit
dl
rm
Edit:
/snap/core22/2411/etc/apparmor.d/abstractions/ubuntu-helpers
(3791B)
# Lenient profile that is intended to be used when 'Ux' is desired but # does not provide enough environment sanitizing. This effectively is an # open profile that blacklists certain known dangerous files and also # does not allow any capabilities. For example, it will not allow 'm' on files # owned be the user invoking the program. While this provides some additional # protection, please use with care as applications running under this profile # are effectively running without any AppArmor protection. Use this profile # only if the process absolutely must be run (effectively) unconfined. # # Usage: # Because this abstraction defines the sanitized_helper profile, it must only # be included once. Therefore this abstraction should typically not be # included in other abstractions so as to avoid parser errors regarding # multiple definitions. # # Limitations: # 1. This does not work for root owned processes, because of the way we use # owner matching in the sanitized helper. We could do a better job with # this to support root, but it would make the policy harder to understand # and going unconfined as root is not desirable any way. # # 2. For this sanitized_helper to work, the program running in the sanitized # environment must open symlinks directly in order for AppArmor to mediate # it. This is confirmed to work with: # - compiled code which can load shared libraries # - python imports # It is known not to work with: # - perl includes # 3. Sanitizing ruby and java # # Use at your own risk. This profile was developed as an interim workaround for # LP: #851986 until AppArmor utilizes proper environment filtering. abi <abi/3.0>, profile sanitized_helper { include <abstractions/base> include <abstractions/X> # Allow all networking network inet, network inet6, # Allow all DBus communications include <abstractions/dbus-session-strict> include <abstractions/dbus-strict> dbus, # Needed for Google Chrome ptrace (trace) peer=**//sanitized_helper, # Allow exec of anything, but under this profile. Allow transition # to other profiles if they exist. /{usr/,usr/local/,}{bin,sbin}/* Pixr, # Allow exec of libexec applications in /usr/lib* and /usr/local/lib* /usr/{,local/}lib*/{,**/}* Pixr, # Allow exec of software-center scripts. We may need to allow wider # permissions for /usr/share, but for now just do this. (LP: #972367) /usr/share/software-center/* Pixr, # Allow exec of texlive font build scripts (LP: #1010909) /usr/share/texlive/texmf{,-dist}/web2c/{,**/}* Pixr, # While the chromium and chrome sandboxes are setuid root, they only link # in limited libraries so glibc's secure execution should be enough to not # require the santized_helper (ie, LD_PRELOAD will only use standard system # paths (man ld.so)). /usr/lib/chromium-browser/chromium-browser-sandbox PUxr, /usr/lib/chromium{,-browser}/chrome-sandbox PUxr, /opt/google/chrome{,-beta,-unstable}/chrome-sandbox PUxr, /opt/google/chrome{,-beta,-unstable}/google-chrome Pixr, /opt/google/chrome{,-beta,-unstable}/chrome Pixr, /opt/google/chrome{,-beta,-unstable}/chrome_crashpad_handler Pixr, /opt/google/chrome{,-beta,-unstable}/{,**/}lib*.so{,.*} m, # The same is needed for Brave /opt/brave.com/brave{,-beta,-dev,-nightly}/chrome-sandbox PUxr, /opt/brave.com/brave{,-beta,-dev,-nightly}/brave-browser{,-beta,-dev,-nightly} Pixr, /opt/brave.com/brave{,-beta,-dev,-nightly}/brave Pixr, /opt/brave.com/brave{,-beta,-dev,-nightly}/{,**/}lib*.so{,.*} m, # Full access / r, /** rwkl, /{,usr/,usr/local/}lib{,32,64}/{,**/}*.so{,.*} m, # Dangerous files audit deny owner /**/* m, # compiled libraries audit deny owner /**/*.py* r, # python imports }
Save
cmd:
run