From ab53a29f68ec4306ff9a775d5bcfc34981174b0c Mon Sep 17 00:00:00 2001 From: odomingao Date: Thu, 15 Aug 2024 14:50:20 -0300 Subject: [PATCH] Add tor profile --- apparmor.d/profiles-s-z/tor | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) create mode 100644 apparmor.d/profiles-s-z/tor diff --git a/apparmor.d/profiles-s-z/tor b/apparmor.d/profiles-s-z/tor new file mode 100644 index 000000000..aacfc5565 --- /dev/null +++ b/apparmor.d/profiles-s-z/tor @@ -0,0 +1,32 @@ +# apparmor.d - Full set of apparmor profiles +# Copyright (C) 2024 odomingao +# SPDX-License-Identifier: GPL-2.0-only + +abi , + +include + +@{exec_path} = @{bin}/tor +profile tor @{exec_path} { + include + include + + capability setgid, + capability setuid, + + network inet dgram, + network inet stream, + network netlink raw, + + @{exec_path} mr, + + /usr/share/tor/{,**} r, + + owner /etc/tor/torrc r, + + owner /var/lib/tor/{,**} rwk, + + include if exists +} + +# vim:syntax=apparmor