2020-10-05 11:06:34 +00:00
|
|
|
# Last Modified: Mon Oct 5 10:19:40 2020
|
|
|
|
#include <tunables/global>
|
|
|
|
|
|
|
|
# based on https://github.com/progmaticltd/homebox/blob/master/install/playbooks/roles/rspamd/templates/apparmor.d/usr.bin.rspamd
|
|
|
|
|
2020-10-09 18:01:48 +00:00
|
|
|
profile rspamd /usr/bin/rspamd {
|
2020-10-05 11:06:34 +00:00
|
|
|
#include <abstractions/base>
|
|
|
|
#include <abstractions/nameservice>
|
|
|
|
#include <abstractions/openssl>
|
2020-10-09 18:01:48 +00:00
|
|
|
#include <abstractions/ssl_certs>
|
2020-10-05 11:06:34 +00:00
|
|
|
|
|
|
|
/usr/bin/rspamd mr,
|
2020-10-09 18:01:48 +00:00
|
|
|
|
|
|
|
/etc/rspamd/** r,
|
|
|
|
|
|
|
|
/srv/www/webapps/rspamd/ r,
|
|
|
|
/srv/www/webapps/rspamd/** r,
|
2020-10-05 11:06:34 +00:00
|
|
|
/usr/share/rspamd/ r,
|
|
|
|
/usr/share/rspamd/** r,
|
2020-10-09 18:01:48 +00:00
|
|
|
|
2020-10-05 11:06:34 +00:00
|
|
|
/var/lib/rspamd/ r,
|
|
|
|
/var/lib/rspamd/** rwk,
|
2020-10-09 18:01:48 +00:00
|
|
|
|
2020-10-05 11:06:34 +00:00
|
|
|
/var/log/rspamd/rspamd.log* rwk,
|
|
|
|
/{var/,}run/rspamd/* rwk,
|
|
|
|
|
2020-10-09 18:01:48 +00:00
|
|
|
/dev/shm/rhm.* rw,
|
|
|
|
/etc/magic r,
|
|
|
|
/proc/sys/kernel/random/uuid r,
|
|
|
|
|
|
|
|
/usr/share/icu/*/icu*.dat r,
|
|
|
|
|
|
|
|
#include if exists <local/usr.bin.rspamd>
|
|
|
|
#include if exists <local/rspamd>
|
|
|
|
}
|