Linux

Where Are AppArmor Profiles Stored on Linux?

AppArmor keeps mandatory-access profiles as text files in etc apparmor.d, one file per confined program.

Last updated

AppArmor profiles are plain text in /etc/apparmor.d. Filenames usually mirror the confined binary with slashes turned to dots (usr.sbin.cupsd) or just use the app name. Helpers live alongside: abstractions, tunables, a local override dir, and disable and force-complain symlink dirs.

Editing is half the workflow. After changing a profile, reload it with apparmor_parser -r and confirm under /sys/kernel/security/apparmor/profiles. To silence a profile without deleting it, symlink it into disable and reload. Local tweaks belong in the local subdirectory so package updates do not clobber them.

Where Linux stores this, by platform

Linux
/etc/apparmor.d

List with sudo ls since most files are root-owned. Check loaded state in /sys/kernel/security/apparmor/profiles. Ubuntu documents this layout; other distros match it.

Frequently asked questions

How do I disable one AppArmor profile?

Symlink its file into /etc/apparmor.d/disable and reload with the parser. Verify it vanished from the loaded profiles list before calling it done.

Where do my own additions go so updates keep them?

In /etc/apparmor.d/local for per-profile additions, using the include hook the stock profile provides. Tunables and custom variables go under tunables. Avoid editing shipped abstractions directly.

Notice an outdated path? Let us know.