sbin.dhcpcd (1013B)
- # Copyright 2020-2023 Haelwenn (lanodan) Monnier <contact+apparmor.d@hacktivis.me>
- # Distributed under the terms of the GNU General Public License v2
- include <tunables/global>
- /sbin/dhcpcd flags=(complain) {
- include <abstractions/base>
- include <abstractions/consoles>
- include <abstractions/nameservice>
- capability net_admin,
- capability net_raw,
- capability sys_chroot,
- capability setgid,
- capability setuid,
- signal receive set=term,
- signal send peer="ntpd",
- /lib{,64}/dhcpcd/dhcpcd-run-hooks ix,
- /sbin/dhcpcd mr,
- owner /etc/dhcpcd.conf r,
- /etc/udev/udev.conf r,
- /run/udev/data/* r,
- /sys/devices/**/net/**/uevent r,
- /sys/devices/virtual/net/**/uevent r,
- owner /proc/*/mountinfo r,
- owner /proc/*/net/if_inet6 r,
- owner /proc/*/stat r,
- /proc/cpuinfo r,
- /proc/sys/kernel/hostname r,
- owner /proc/sys/net/** rw,
- owner /run/dhcpcd/** rwlk,
- owner /var/lib/dhcpcd/* rw,
- /bin/gsed rix,
- /usr/bin/cmp rix,
- /bin/rm rix,
- /etc/ntpd.conf r,
- unix (getattr),
- }