File: snapd.apparmor.service.in

package info (click to toggle)
snapd 2.72-1
  • links: PTS, VCS
  • area: main
  • in suites: sid
  • size: 80,412 kB
  • sloc: sh: 16,506; ansic: 16,211; python: 11,213; makefile: 1,919; exp: 190; awk: 58; xml: 22
file content (32 lines) | stat: -rw-r--r-- 1,345 bytes parent folder | download | duplicates (2)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
# This systemd unit is needed on distributions that use apparmor but don't have
# special support for loading snapd apparmor profiles. Until upstream apparmor
# user-space release contains a systemd unit that is actually shipped by
# distributors and that contains the necessary extension points for snapd the
# apparmor profiles for snap applications need to be loaded separately from
# other applications.
[Unit]
Description=Load AppArmor profiles managed internally by snapd
DefaultDependencies=no
Before=sysinit.target
# This dependency is meant to ensure that apparmor initialization (whatever that might entail) is complete.
After=apparmor.service
# In case of re-execution, snapd snap has to be mounted. apparmor.service has
# a dependency to local-fs.target which is enough in theory. But in case
# this dependency dispappears, it is better to have an explicit dependency to
# snapd.mount.target here.
After=snapd.mounts.target
Wants=snapd.mounts.target
ConditionSecurity=apparmor
RequiresMountsFor=/var/cache/apparmor /var/lib/snapd/apparmor/profiles
# This is handled by snapd
# X-Snapd-Snap: do-not-start

[Service]
Type=oneshot
ExecStart=@libexecdir@/snapd/snapd-apparmor start
EnvironmentFile=-@SNAPD_ENVIRONMENT_FILE@
EnvironmentFile=-/var/lib/snapd/environment/snapd.conf
RemainAfterExit=yes

[Install]
WantedBy=multi-user.target