检查apparmor的状态:
systemctl status apparmor
示例脚本:
mkdir /root/apparmor
cd /root/apparmor
nano myscript.sh
#! /bin/bash
touch /tmp/file.txt
echo " New File created "
rm -f /tmp/file.txt
echo " New file removed "
chmod +x myscript.sh
安装Apparmor实用程序:
apt install apparmor-utils
生成一个新的配置文件:
aa-genprof ./myscript.sh
./myscript.sh (from new tab)
验证新的配置文件:
cat /etc/apparmor.d/root.tt.script.sh
aa-stat