mosquitto.apparmor 620 B

12345678910111213141516171819202122232425262728
  1. /usr/sbin/mosquitto {
  2. #include <abstractions/base>
  3. #include <abstractions/nameservice>
  4. /usr/sbin/mosquitto r,
  5. /etc/mosquitto/mosquitto.conf r,
  6. /etc/mosquitto/ca_certificates/* r,
  7. /etc/mosquitto/certs/* r,
  8. /etc/mosquitto/conf.d/* r,
  9. /var/lib/mosquitto/ r,
  10. /var/lib/mosquitto/mosquitto.db rwk,
  11. /var/lib/mosquitto/mosquitto.db.new rwk,
  12. /var/run/mosquitto.pid rw,
  13. network inet stream,
  14. network inet6 stream,
  15. network inet dgram,
  16. network inet6 dgram,
  17. # For drop privileges
  18. capability setgid,
  19. capability setuid,
  20. # For tcp-wrappers
  21. /lib{,32,64}/libwrap.so* rm,
  22. /etc/hosts.allow r,
  23. /etc/hosts.deny r,
  24. }