# apparmor.d - Full set of apparmor profiles
# Copyright (C) 2025 Alexandre Pujol <alexandre@pujol.io>
# SPDX-License-Identifier: GPL-2.0-only

#aa:lint ignore=too-wide

# *Part of the `systemd` (as PID 1) profile.*
#
# `sd` is a profile for **S**ystem**D**-executor run as root, it is used to run
# all services files and to encapsulate stacked services profiles (hence the
# short name).
#
# It aims at reducing the size of the `systemd` profile.
#
# !!! info
#
#     Distributions and other programs can add rules in the `usr/sd.d` directory
#

abi <abi/4.0>,

include <tunables/global>

@{exec_path} = @{bin}/systemd-executor
@{att} = /att/sd/
profile sd flags=(attach_disconnected,attach_disconnected.path=@{att},mediate_deleted) {
  include <abstractions/attached/base>
  include <abstractions/authentication>
  include <abstractions/bus-system>
  include <abstractions/attached/consoles>
  include <abstractions/devices-usb>
  include <abstractions/disks-write>
  include <abstractions/attached/nameservice-strict>
  include <abstractions/wutmp>

  all, # FIXME: this is temporary

  change_profile,

  @{exec_path} mr,

  @{bin}/**                                       mpx,
  @{sbin}/**                                      mpx,
  @{lib}/**                                        px,
  /etc/cron.*/*                                    px,
  /etc/init.d/*                                    px,
  /etc/update-motd.d/*                             px,
  /usr/share/*/**                                  px,

  # Systemd user: systemd --user
  @{lib}/systemd/systemd                           px -> systemd-user,

  # Mount operations from services and systemd
  @{bin}/mount                                     px -> sd-mount,
  @{bin}/umount                                    px -> sd-umount,

  # Unit services using systemctl
  @{bin}/systemctl                                 cx -> systemctl,

  # Unit services
  @{bin}/kill                                      cx -> kill,

  profile systemctl flags=(attach_disconnected,attach_disconnected.path=@{att},mediate_deleted,complain) {
    include <abstractions/attached/base>
    include <abstractions/app/systemctl>

    include if exists <usr/sd_systemctl.d>
    include if exists <local/sd_systemctl>
  }

  profile kill flags=(attach_disconnected,attach_disconnected.path=@{att},mediate_deleted,complain) {
    include <abstractions/attached/base>

    signal send,

    @{bin}/kill mr,

    include if exists <local/sd_kill>
  }

  include if exists <usr/sd.d>
  include if exists <local/sd>
}

# vim:syntax=apparmor
