diff --git a/contrib/apparmor/usr.bin.yggdrasil b/contrib/apparmor/usr.bin.yggdrasil new file mode 100644 index 0000000..e31a27b --- /dev/null +++ b/contrib/apparmor/usr.bin.yggdrasil @@ -0,0 +1,23 @@ +# Last Modified: Sat Mar 9 06:08:02 2019 +#include + +/usr/bin/yggdrasil { + #include + + capability net_admin, + + network inet stream, + network inet dgram, + network inet6 dgram, + network inet6 stream, + network netlink raw, + + /lib/@{multiarch}/ld-*.so mr, + /proc/sys/net/core/somaxconn r, + /dev/net/tun rw, + + /usr/bin/yggdrasil mr, + /etc/yggdrasil.conf rw, + /run/yggdrasil.sock rw, + +}