Where Are AppArmor Profiles Stored on Linux?
AppArmor keeps mandatory-access profiles as text files in etc apparmor.d, one file per confined program.
Last updated
AppArmor profiles are plain text in /etc/apparmor.d. Filenames usually mirror the confined binary with slashes turned to dots (usr.sbin.cupsd) or just use the app name. Helpers live alongside: abstractions, tunables, a local override dir, and disable and force-complain symlink dirs.
Editing is half the workflow. After changing a profile, reload it with apparmor_parser -r and confirm under /sys/kernel/security/apparmor/profiles. To silence a profile without deleting it, symlink it into disable and reload. Local tweaks belong in the local subdirectory so package updates do not clobber them.
Where Linux stores this, by platform
/etc/apparmor.d
List with sudo ls since most files are root-owned. Check loaded state in /sys/kernel/security/apparmor/profiles. Ubuntu documents this layout; other distros match it.
Frequently asked questions
How do I disable one AppArmor profile?
Symlink its file into /etc/apparmor.d/disable and reload with the parser. Verify it vanished from the loaded profiles list before calling it done.
Where do my own additions go so updates keep them?
In /etc/apparmor.d/local for per-profile additions, using the include hook the stock profile provides. Tunables and custom variables go under tunables. Avoid editing shipped abstractions directly.
Notice an outdated path? Let us know.