home *** CD-ROM | disk | FTP | other *** search
- # vim:syntax=apparmor
- # Last Modified: Wed Feb 3 07:58:30 2009
- # Author: Jamie Strandboge <jamie@canonical.com>
- #include <tunables/global>
-
- /usr/sbin/tcpdump {
- #include <abstractions/base>
- #include <abstractions/nameservice>
- #include <abstractions/user-tmp>
-
- capability net_raw,
- capability setuid,
- capability setgid,
- capability dac_override,
- network raw,
- network packet,
-
- # for -D
- capability sys_module,
- @{PROC}/bus/usb/ r,
- @{PROC}/bus/usb/** r,
-
- # for -F and -w
- audit deny @{HOME}/.* mrwkl,
- audit deny @{HOME}/.*/ rw,
- audit deny @{HOME}/.*/** mrwkl,
- audit deny @{HOME}/bin/ rw,
- audit deny @{HOME}/bin/** mrwkl,
- @{HOME}/ r,
- @{HOME}/** rw,
-
- /usr/sbin/tcpdump r,
- }
-