samba (1275B)
- # vim:syntax=apparmor
 - # ------------------------------------------------------------------
 - #
 - # Copyright (C) 2009-2010 Canonical Ltd.
 - #
 - # This program is free software; you can redistribute it and/or
 - # modify it under the terms of version 2 of the GNU General Public
 - # License published by the Free Software Foundation.
 - #
 - # ------------------------------------------------------------------
 - abi <abi/3.0>,
 - /etc/samba/* r,
 - /usr/lib*/ldb/*.so mr,
 - /usr/lib*/ldb2/*.so mr,
 - /usr/lib*/ldb2/modules/ldb/*.so mr,
 - /usr/lib*/samba/ldb/*.so mr,
 - /usr/share/samba/*.dat r,
 - /usr/share/samba/codepages/{lowcase,upcase,valid}.dat r,
 - /var/cache/samba/ w,
 - /var/cache/samba/lck/* rwk,
 - /var/lib/samba/** rwk,
 - /var/log/samba/cores/ rw,
 - /var/log/samba/cores/** rw,
 - /var/log/samba/* rw,
 - @{run}/{,lock/}samba/ w,
 - @{run}/{,lock/}samba/*.tdb rwk,
 - @{run}/{,lock/}samba/msg.{lock,sock}/ rwk,
 - @{run}/{,lock/}samba/msg.{lock,sock}/[0-9]* rwk,
 - /var/cache/samba/*.tdb rwk,
 - /var/cache/samba/msg.lock/ rwk,
 - /var/cache/samba/msg.lock/[0-9]* rwk,
 - # required for clustering
 - /var/lib/ctdb/** rwk,
 - deny capability net_admin, # noisy setsockopt() calls from systemd
 - # Include additions to the abstraction
 - include if exists <abstractions/samba.d>