#!/bin/bash

## Copyright (C) 2020 - 2025 ENCRYPTED SUPPORT LLC <adrelanos@whonix.org>
## See the file COPYING for copying conditions.

## https://forums.whonix.org/t/full-system-apparmor-policy-testers-wanted/10381/22

## Not using sudo hardcoded below.
## https://forums.whonix.org/t/full-system-apparmor-policy-testers-wanted/10381/29
set -o errexit
set -o nounset
set -o pipefail
set -o errtrace
shopt -s inherit_errexit
shopt -s shift_verbose

if [ "$(id -u)" != "0" ]; then
   printf '%s\n' "ERROR: Must run as root." >&2
   printf '%s\n' "sudo $0" >&2
   exit 112
fi

## Default.
exit_code=0

## Parses AppArmor denial logs to hide unnecessary information and remove duplicates.

output_denied="$(journalctl _TRANSPORT=audit --output cat "${@}" | grep "DENIED" | sed -e 's/pid=.* comm/comm/g' | sed -e 's/ fsuid.*//g' | awk '!x[$0]++')"

if [ ! "${output_denied}" = "" ]; then
   exit_code=1
   printf '%s\n' "${output_denied}"
fi

output_allowed="$(journalctl _TRANSPORT=audit --output cat "${@}" | grep "ALLOWED" | sed -e 's/pid=.* comm/comm/g' | sed -e 's/ fsuid.*//g' | awk '!x[$0]++')"

if [ ! "${output_allowed}" = "" ]; then
   exit_code=1
   printf '%s\n' "${output_allowed}"
fi

exit "${exit_code}"
