# vim:syntax=apparmor #include <tunables/global> /usr/sbin/tcpdump { #include <abstractions/base> #include <abstractions/nameservice> #include <abstractions/user-tmp> capability net_raw, capability setuid, capability setgid, capability dac_override, network raw, network packet, # for -D @{PROC}/bus/usb/ r, @{PROC}/bus/usb/** r, # for finding an interface @{PROC}/[0-9]*/net/dev r, /sys/bus/usb/devices/ r, /sys/class/net/ r, /sys/devices/**/net/* r, # for -j capability net_admin, # for tracing USB bus, which libpcap supports /dev/usbmon* r, /dev/bus/usb/ r, /dev/bus/usb/** r, # for init_etherarray(), with -e /etc/ethers r, # for USB probing (see libpcap-1.1.x/pcap-usb-linux.c:probe_devices()) /dev/bus/usb/**/[0-9]* w, # for -z /{usr/,}bin/gzip ixr, /{usr/,}bin/bzip2 ixr, # for -F and -w audit deny @{HOME}/.* mrwkl, audit deny @{HOME}/.*/ rw, audit deny @{HOME}/.*/** mrwkl, audit deny @{HOME}/bin/ rw, audit deny @{HOME}/bin/** mrwkl, owner @{HOME}/ r, owner @{HOME}/** rw, # for -r, -F and -w /**.[pP][cC][aA][pP] rw, # for convenience with -r (ie, read pcap files from other sources) /var/log/snort/*log* r, /usr/sbin/tcpdump mr, # allow printing to stdout/stderr when inside a container # (LP: #1667016) /dev/pts/* rw, # Site-specific additions and overrides. See local/README for details. #include <local/usr.sbin.tcpdump> }
Name | Type | Size | Permission | Actions |
---|---|---|---|---|
abstractions | Folder | 0755 |
|
|
cache | Folder | 0755 |
|
|
disable | Folder | 0755 |
|
|
force-complain | Folder | 0755 |
|
|
local | Folder | 0755 |
|
|
lxc | Folder | 0755 |
|
|
tunables | Folder | 0755 |
|
|
lxc-containers | File | 198 B | 0644 |
|
sbin.dhclient | File | 3.12 KB | 0644 |
|
system_tor | File | 684 B | 0644 |
|
usr.bin.lxc-start | File | 125 B | 0644 |
|
usr.bin.man | File | 2.79 KB | 0644 |
|
usr.lib.snapd.snap-confine.real | File | 27.82 KB | 0644 |
|
usr.sbin.mysqld | File | 1.75 KB | 0644 |
|
usr.sbin.rsyslogd | File | 1.51 KB | 0644 |
|
usr.sbin.tcpdump | File | 1.42 KB | 0644 |
|