1 2 3 4 | Rule:
/{,usr/}lib{,32,64,x32}/{,@{multiarch}/}libcap.so* mr,
[ 2226.108616] audit: type=1400 audit(1511190324.179:369): apparmor="DENIED" operation="open" profile="/usr/lib/snapd/snap-confine" name="/lib/x86_64-linux-gnu/libcap.so.2.25" pid=4361 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
|