# apparmor.d - Full set of apparmor profiles # Copyright (C) 2021 Alexandre Pujol # SPDX-License-Identifier: GPL-2.0-only abi , include @{exec_path} = @{bin}/auditd profile auditd @{exec_path} flags=(attach_disconnected) { include include capability audit_control, capability chown, capability fsetid, capability sys_nice, capability sys_resource, network netlink raw, @{exec_path} mr, /etc/audit/{,**} r, /etc/machine-id r, /var/log/audit/{,**} rw, @{run}/systemd/journal/dev-log w, owner @{run}/auditd.pid rwl, owner @{run}/auditd.state rw, owner @{PROC}/@{pid}/attr/current r, owner @{PROC}/@{pid}/loginuid r, owner @{PROC}/@{pid}/oom_score_adj rw, owner @{PROC}/@{pid}/sessionid r, include if exists }