Re: [apparmor] AppArmor profile: requested_mask and denied_mask = "c", "x".

2015-12-19 Thread daniel curtis
​Hi Christian, So, if "c" means create file/directory then if AppArmor audit entries (for example from log files etc.) contains something like this: operation="mkdir", requested_mask="c", denied_mask="c" Then, rule in an AppArmor application profile should look like: /home/user/.app/ w, Am I

Re: [apparmor] AppArmor profile: requested_mask and denied_mask = "c", "x".

2015-12-19 Thread John Johansen
On 12/19/2015 10:27 AM, daniel curtis wrote: > > ​Hi Christian, > > So, if "c" means create file/directory then if AppArmor audit > entries (for example from log files etc.) contains something like > this: > > operation="mkdir", requested_mask="c", denied_mask="c" > > Then, rule in an AppArmor