3.0 AppArmor Command Line Tools

autodep

Guess basic AppArmor profile requirements. autodep creates an approximate profile for the program or application examined. The resulting profile is called approximate because it does not necessarily contain all of the profile entries that the program needs to be confined properly.

complain

Set an AppArmor profile to complain mode.

enforce

Set an AppArmor profile to enforce mode from complain mode.

genprof

Generate a profile. When running, you must specify a program to profile. If the specified program is not an absolute path, genprof searches the $PATH variable. If a profile does not exist, genprof creates one using autodep.

logprof

Manage AppArmor profiles. logprof is an interactive tool used to review the learning or complain mode output found in the AppArmor syslog entries and to generate new entries in AppArmor profiles.

unconfined

Output a list of processes with tcp or udp ports that do not have AppArmor profiles loaded.