You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过AppArmor规则阻止所有应用删除指定目录及其子目录内的内容(允许创建与写入)

如何通过AppArmor规则阻止所有应用删除指定目录及其子目录内的内容(允许创建与写入)

Hey, I get what you're trying to do here—blocking deletes while keeping create/write access is a tricky one with standard ACLs, and I see you ran into issues with both chattr +a and your first AppArmor rule. Let's break down how to fix this properly.

先说说chattr +a的问题

The chattr +a behavior you noticed is totally normal: it only applies to the exact directory you run it on, not any new subdirectories created afterward. You could hack together a script with inotify to auto-apply the attribute to new subdirs, but AppArmor is a cleaner, more scalable solution for this kind of restriction.

你的初始AppArmor规则为什么没生效

Your first profile had two key problems:

  1. It wasn't attached to any running processes, so no apps were actually using the rules.
  2. You only denied directory deletion (D), not file deletion (d)—that's why files in new subdirs could still be removed.

正确的AppArmor配置方案

方案1:通用拦截(覆盖所有未被其他Profile管理的进程)

Create a profile that attaches to all "disconnected" processes (those not already covered by another AppArmor profile) and blocks deletes in your target directory:

  1. Create a new profile file at /etc/apparmor.d/prevent-testdir-delete with this content:
# Profile to block deletes in /home/don/testdir while allowing create/write
profile prevent-testdir-delete attach_disconnected {
    # Allow full read/write/create/execute access in the target directory and subdirs
    /home/don/testdir/ rwlix,
    /home/don/testdir/** rwlix,

    # Explicitly deny file deletion (d) and directory deletion (D)
    deny /home/don/testdir/** d,
    deny /home/don/testdir/** D,

    # Allow normal operations everywhere else (adjust this if you need tighter restrictions)
    /** rwlkix,
}
  1. Load the profile to activate it:
sudo apparmor_parser -r /etc/apparmor.d/prevent-testdir-delete

方案2:针对特定删除工具(比如rm)

If you want to target specific tools that handle deletions (like rm), this is often simpler and more focused:

  1. Create /etc/apparmor.d/usr.bin.rm with:
profile /usr/bin/rm {
    # Allow normal delete operations everywhere except our target directory
    /** rwlkix,

    # Block deletes in testdir and all subdirectories
    deny /home/don/testdir/** d,
    deny /home/don/testdir/** D,
}
  1. Load the profile:
sudo apparmor_parser -r /etc/apparmor.d/usr.bin.rm

验证规则是否生效

Test it out by trying to delete a file in the target directory:

rm /home/don/testdir/subdir/file.txt

You should get a permission denied error. But you can still create or edit files without issues:

echo "new content" > /home/don/testdir/new_file.txt
touch /home/don/testdir/subdir/new_subfile.txt

额外注意事项

  • If you have apps that already have their own AppArmor profiles (like Firefox, VS Code, etc.), you'll need to add the deny rules to their respective profile files (located in /etc/apparmor.d/) to cover those processes.
  • To ensure profiles load automatically on system boot, make sure AppArmor is enabled:
    sudo systemctl enable --now apparmor
    

备注:内容来源于stack exchange,提问作者u4963840

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.16 07:33:16