Home / Alt manpages / aa-features-abi(1)

  • aa-features-abi(1)
  • User command
  • linux

Capture and Validate an AppArmor Feature ABI

You will finish with a saved AppArmor feature ABI that you can inspect, compare and feed into another AppArmor tool. The workflow uses aa-features-abi from AppArmor 4.0.1, installed here as package version 4.0.1really4.0.1-0ubuntu0.24.04.7.

Allow about ten minutes. You need a shell, the AppArmor utilities package and a writable directory for the saved file. Reading the kernel ABI is normally unprivileged on this machine. Writing a file needs ordinary filesystem permission for the destination, not automatically sudo.

1. Confirm the installed command

Start by checking the binary and package version. This is read-only and does not need elevated privileges:

$ command -v aa-features-abi
/usr/bin/aa-features-abi
$ dpkg-query -W -f='${Package} ${Version}\n' apparmor
apparmor 4.0.1really4.0.1-0ubuntu0.24.04.7
$ aa-features-abi --help
USAGE: aa-features-abi [OPTIONS] <SOURCE> [OUTPUT OPTIONS]

The installed help is the useful contract for this release. A source is required: use --extract or --file. Output defaults to standard output, or you can select a destination with --write.

Checkpoint

If command -v finds nothing, stop and install or repair the AppArmor utilities through your normal package-management process. Do not copy a similarly named script into place.

2. Extract the kernel feature ABI to the terminal

Use --extract with --stdout for a first, non-destructive check:

$ aa-features-abi --extract --stdout
capability {0xffffff
}
caps {extended {yes
}
mask {chown dac_override ...
}
}
dbus {mask {acquire send receive
}

The exact feature list belongs to the running kernel and AppArmor configuration, so your output will differ. The braces and feature names are data, not a report that the command has changed policy. Keep the command's exit status if you are using it in a script:

$ aa-features-abi --extract --stdout >/dev/null
$ printf 'exit status: %s\n' "$?"
exit status: 0

Do not treat a short preview made with head as a complete ABI. Piping a large capture to a consumer that exits early can also produce a broken-pipe diagnostic, so capture the complete stream when the file matters.

3. Save a complete ABI for review

Choose a path that is writable and is not used by a running service. The following example writes under /tmp, so it is suitable for a disposable test. The command changes the filesystem by creating or replacing that named file:

$ abi_file=$(mktemp /tmp/apparmor-features-abi.XXXXXX)
$ aa-features-abi --extract --write "$abi_file"
$ printf 'saved %s bytes to %s\n' "$(wc -c <"$abi_file")" "$abi_file"
saved 1234 bytes to /tmp/apparmor-features-abi.A1b2C3

The byte count and temporary suffix are examples. Check that the file exists and is non-empty before passing it on:

$ test -s "$abi_file" && echo 'feature ABI capture is non-empty'
feature ABI capture is non-empty

Keep this temporary file until the review and round-trip checks below are complete. For a persistent path, do not overwrite a system-managed ABI or a file used by policy tooling without checking its owner and backup process first. A feature ABI describes the available feature set; it is not a policy file and writing one does not load it into the kernel.

4. Read a saved ABI and write a second copy

--file makes the saved file the source instead of the kernel. With no output option, the data goes to standard output:

$ aa-features-abi --file "$abi_file" --stdout
capability {0xffffff
}
caps {extended {yes
}

To validate the file as input without displaying all of it, send the output to a second temporary file and compare the two byte streams:

$ copy_file=$(mktemp /tmp/apparmor-features-abi-copy.XXXXXX)
$ aa-features-abi --file "$abi_file" --write "$copy_file"
$ cmp -- "$abi_file" "$copy_file"
$ echo 'saved ABI round-trip matches'
saved ABI round-trip matches

Here, "validate" means that the installed command accepted the file and reproduced it. It does not mean that the ABI is appropriate for a different kernel. Compare captures only when you know which kernel and AppArmor package produced them.

5. Diagnose the common failures

Every invocation needs a source option. Running only an output option is an argument error:

$ aa-features-abi --stdout
USAGE: (null) [OPTIONS] <SOURCE> [OUTPUT OPTIONS]
Output AppArmor feature abi from SOURCE to OUTPUT
$ printf 'exit status: %s\n' "$?"
exit status: 1

This release prints its usage text when the source is missing. The program name may appear as (null) in that diagnostic. Rely on the non-zero status and the help output when scripting. A missing input file is also a failure, not an empty ABI:

$ aa-features-abi --file /path/to/missing-features-abi --stdout
aa-features-abi: ERROR: failed to open file '/path/to/missing-features-abi' - No such file or directory
$ printf 'exit status: %s\n' "$?"
exit status: 1

If --write cannot create the destination, check the parent directory, ownership and available space. Use sudo only when the intended destination genuinely requires it and you have reviewed the consequences. Do not grant broad write permission just to make a capture succeed.

The short forms are -x for extraction, -f FILE for an input file and -w FILE for the output file. Long forms are clearer in maintenance scripts. --debug adds debugging messages and --verbose shows statistics; neither option repairs an invalid path or changes AppArmor policy.

When the temporary review is finished, remove only the exact files you created:

$ rm -- "$abi_file" "$copy_file"
$ test ! -e "$abi_file" && test ! -e "$copy_file" && echo 'temporary captures removed'
temporary captures removed

Done means

  • You confirmed the AppArmor package and command version.
  • You extracted a complete feature ABI and checked its exit status.
  • You saved it only to a path whose ownership and purpose you understood.
  • You read a saved ABI with --file and checked a round-trip with cmp.
  • You know that the tool reads and writes ABI data; it does not load policy or alter the kernel.
  • You removed disposable captures and kept persistent copies under deliberate change control.