如何通过AppArmor规则阻止所有应用删除指定目录及其子目录内的内容(允许创建与写入)
Hey, I get what you're trying to do here—blocking deletes while keeping create/write access is a tricky one with standard ACLs, and I see you ran into issues with both chattr +a and your first AppArmor rule. Let's break down how to fix this properly.
先说说chattr +a的问题
The chattr +a behavior you noticed is totally normal: it only applies to the exact directory you run it on, not any new subdirectories created afterward. You could hack together a script with inotify to auto-apply the attribute to new subdirs, but AppArmor is a cleaner, more scalable solution for this kind of restriction.
你的初始AppArmor规则为什么没生效
Your first profile had two key problems:
- It wasn't attached to any running processes, so no apps were actually using the rules.
- You only denied directory deletion (
D), not file deletion (d)—that's why files in new subdirs could still be removed.
正确的AppArmor配置方案
方案1:通用拦截(覆盖所有未被其他Profile管理的进程)
Create a profile that attaches to all "disconnected" processes (those not already covered by another AppArmor profile) and blocks deletes in your target directory:
- Create a new profile file at
/etc/apparmor.d/prevent-testdir-deletewith this content:
# Profile to block deletes in /home/don/testdir while allowing create/write profile prevent-testdir-delete attach_disconnected { # Allow full read/write/create/execute access in the target directory and subdirs /home/don/testdir/ rwlix, /home/don/testdir/** rwlix, # Explicitly deny file deletion (d) and directory deletion (D) deny /home/don/testdir/** d, deny /home/don/testdir/** D, # Allow normal operations everywhere else (adjust this if you need tighter restrictions) /** rwlkix, }
- Load the profile to activate it:
sudo apparmor_parser -r /etc/apparmor.d/prevent-testdir-delete
方案2:针对特定删除工具(比如rm)
If you want to target specific tools that handle deletions (like rm), this is often simpler and more focused:
- Create
/etc/apparmor.d/usr.bin.rmwith:
profile /usr/bin/rm { # Allow normal delete operations everywhere except our target directory /** rwlkix, # Block deletes in testdir and all subdirectories deny /home/don/testdir/** d, deny /home/don/testdir/** D, }
- Load the profile:
sudo apparmor_parser -r /etc/apparmor.d/usr.bin.rm
验证规则是否生效
Test it out by trying to delete a file in the target directory:
rm /home/don/testdir/subdir/file.txt
You should get a permission denied error. But you can still create or edit files without issues:
echo "new content" > /home/don/testdir/new_file.txt touch /home/don/testdir/subdir/new_subfile.txt
额外注意事项
- If you have apps that already have their own AppArmor profiles (like Firefox, VS Code, etc.), you'll need to add the deny rules to their respective profile files (located in
/etc/apparmor.d/) to cover those processes. - To ensure profiles load automatically on system boot, make sure AppArmor is enabled:
sudo systemctl enable --now apparmor
备注:内容来源于stack exchange,提问作者u4963840

