apparmor
apparmor
¶
AppArmor awareness for the per-container dnsmasq DNS tiers.
Some distros (Arch/Manjaro, the apparmor.d profile set) ship an
enforcing AppArmor profile for /usr/sbin/dnsmasq that forbids the
shield state directory under the operator's home, so the per-container
dnsmasq cannot read its config and the container would fail to launch.
This module probes for that confinement behaviourally (via dnsmasq
--test — no root needed) and drives a fallback to the lookup tier.
The profile addendum that lets operators keep the dnsmasq tiers is
documented in docs/apparmor.md.
detect_dns_tier_under_apparmor(runner, state_dir, binary)
¶
Pick the DNS tier and report whether AppArmor blocked the dnsmasq at binary.
Returns (tier, apparmor_blocked). apparmor_blocked is True when
the dnsmasq was found but AppArmor confines it from state_dir, so
tier dropped to a static fallback (dig or getent). An empty binary
means the host has no dnsmasq.
Source code in src/terok_shield/dns/apparmor.py
dnsmasq_can_read_state_dir(runner, binary, state_dir)
¶
Return True if the dnsmasq at binary can read a config file inside state_dir.
Writes a throwaway probe config and runs dnsmasq --test on it; a
permission denial (AppArmor) returns False. Parse errors, a missing
binary, or an unwritable probe return True so tier selection never
downgrades spuriously.