#!/bin/bash ## Copyright (C) 2020 - 2025 ENCRYPTED SUPPORT LLC ## See the file COPYING for copying conditions. ## https://forums.whonix.org/t/full-system-apparmor-policy-testers-wanted/10381/22 ## Not using sudo hardcoded below. ## https://forums.whonix.org/t/full-system-apparmor-policy-testers-wanted/10381/29 set -o errexit set -o nounset set -o pipefail set -o errtrace shopt -s inherit_errexit shopt -s shift_verbose if [ "$(id -u)" != "0" ]; then printf '%s\n' "ERROR: Must run as root." >&2 printf '%s\n' "sudo $0" >&2 exit 112 fi ## Default. exit_code=0 ## Parses AppArmor denial logs to hide unnecessary information and remove duplicates. output_denied="$(journalctl _TRANSPORT=audit --output cat "${@}" | grep "DENIED" | sed -e 's/pid=.* comm/comm/g' | sed -e 's/ fsuid.*//g' | awk '!x[$0]++')" if [ ! "${output_denied}" = "" ]; then exit_code=1 printf '%s\n' "${output_denied}" fi output_allowed="$(journalctl _TRANSPORT=audit --output cat "${@}" | grep "ALLOWED" | sed -e 's/pid=.* comm/comm/g' | sed -e 's/ fsuid.*//g' | awk '!x[$0]++')" if [ ! "${output_allowed}" = "" ]; then exit_code=1 printf '%s\n' "${output_allowed}" fi exit "${exit_code}"