evilsocket / evilsocket/opensnitch
[Feature Request] AppArmor label operand
Open
feature
- Dominant language
- Python
- Stars
- 14.1k
- Forks
- 665
- PR merge metrics
- No merged PRs in 30d
Description
### Summary:
On systems that use AppArmor (eg. Ubuntu) every process has a security label assigned, which can be checked by reading the `/proc/pid/attr/apparmor/current` file of that process
I'd like to be able to use that label as an operand in OpenSnitch rules
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reading the existing OpenSnitch rule operand handling and inspect the process label at /proc/pid/attr/apparmor/current. Done means an AppArmor label can be used as an operand in OpenSnitch rules on systems that provide it.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- linux
- Domain
- operating-systems, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100