Skip to content
| Marketplace
Sign in
Visual Studio Code>Programming Languages>AppArmor Language ServerNew to Visual Studio Code? Get it now.
AppArmor Language Server

AppArmor Language Server

Alex Murray

|
19 installs
| (0) | Free
Language support for AppArmor profiles: diagnostics, completions, hover, go-to-definition, formatting, and more.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

AppArmor Language Server

Full-featured language support for AppArmor profiles, powered by apparmor-language-server.

Features

Feature Details
Completions Rule keywords with snippets, all Linux capabilities, network families/types/protocols, signal names, ptrace/mount/dbus/unix permissions, file permission strings, @{variable} names, include abstraction paths, live filesystem path completion
Hover Rich documentation for every keyword, capability, permission character, network family, profile flag, and variable
Diagnostics Unknown capabilities, network types, signal/ptrace/mount/dbus/unix/mqueue/rlimit values; dangerous unconfined exec modes; conflicting flags; conflicting allow+deny; undefined variables; unused variables; unused preamble includes; missing include/abi targets; missing abi declaration; missing tunables/global include; abstractions/nameservice used where nameservice-strict suffices; missing owner qualifier on @{HOME}, /home/, @{run}/user/, /run/user/, and /tmp/ file rules; bare * or [0-9]* in the PID or TID position of a /proc/ path; literal path segment matching a plain variable value in scope (suggests variable substitution); broad recursive home access (@{HOME}/**, @{HOMEDIRS}/**) without abstractions/private-files-strict; @{HOME}/** paired with a deny @{HOME}/.** rule that can be collapsed to @{HOME}/[^.]** without re-enabling other dot-file rules; attach_disconnected flag used without .path= qualifier; attach_disconnected.path or attach_disconnected.ipc used bare without =VALUE (error); attach_disconnected.path= value not starting with / or not following the /att/<profile-name>/ convention; unclosed profiles; subsumed file rules and rules subsumed by broader siblings, transitively included abstractions, or all,; file rules and other rules that can be merged into fewer rules without widening permissions (file-rule-consolidatable, rule-consolidatable); no profile name in the file matches or begins with the document filename (e.g. a file foo may contain profiles whose names start with foo); profile name defined in more than one document; missing include if exists <local/…> at end of profile; inline comment (trailing comment on a rule or directive) missing space after #; available AppArmor abstraction that covers ≥85% of the profile's inline rules (with a code action to insert the include and remove redundant rules); and more — plus apparmor_parser syntax errors when available
Code Actions Quick fixes for flagged diagnostics (e.g. remove duplicate capabilities, add missing abi declaration, add missing tunables/global include, remove unused variable, remove unused include, add missing owner qualifier, replace bare /proc/ PID/TID wildcards with @{pid}/@{pids}/@{tid}, replace literal path segment with matching variable reference, add missing abstractions/private-files-strict include or rewrite @{HOME}/** to @{HOME}/[^.]** (two alternative fixes for broad home access), collapse @{HOME}/** + deny @{HOME}/.** pair to @{HOME}/[^.]**, rename profile to match filename, add missing include if exists <local/…>, replace bare attach_disconnected or bare attach_disconnected.path with the qualified .path= form, correct a non-conventional attach_disconnected.path= value, add space after # in comments, merge consolidatable file rules into a single rule with combined permissions, merge consolidatable rules of the same type into a single rule, replace matching inline rules with include <abstractions/…>, "Did you mean X?" typo corrections for unknown capabilities, permission tokens, flags, keywords, and undefined variable names, annotate to suppress a warning)
Audit-log rule suggestions Source code actions (right-click → Source Action…) generated from AppArmor audit events (DENIED, and complain-mode ALLOWED): denials recorded for the profile being edited are mapped to the corresponding rules the same way aa-logprof does (merging separate denials on the same path into one rule with the combined permissions), filtered to those the profile does not already grant, and offered for insertion — individually, all at once, or as aa-logprof-style widened glob variants (dir/*.ext, dir/*, parent/**) — ranked by severity.db risk score. An information-level diagnostic on the profile header announces how many suggestions are available
Code Lens Summary annotations above key lines: rule and hat counts on profile/hat headers; kernel policy status ("loaded: enforce", "loaded: complain", or "not loaded"); a "modified since last load" indicator when the source has been edited since the last load; reference counts on @{VAR} definitions; a clickable lens that inserts all audit-log suggested rules; and a clickable lens that removes all subsumed rules in one edit. Rule/variable counts for resolved include directives are surfaced on hover instead. Disable with apparmor.codeLens.enable
Document Links include and abi paths rendered as inline hyperlinks; clicking navigates to the target file
Go to Definition Jump from include <…> to the target file; jump to profile definitions; follow exec transitions and change_profile rules to the target profile
Call Hierarchy Incoming: which profiles exec-transition or change_profile into a given profile; outgoing: which profiles a given profile transitions to
Formatting Normalise indentation, sort capability and permission lists, ensure trailing commas, align consecutive file rules, wrap long rules, normalise #include → include, collapse blank lines
Semantic Tokens Theme-aware syntax highlighting for rule keywords, qualifiers, paths, permissions, variables, and more; dangerous unconfined-exec permissions and confinement-escaping capabilities are flagged as warnings, and xattrs=(…) pairs are highlighted
Document Symbols Outline view showing all profiles, hats, capabilities, file rules, includes and variables
Folding Collapse profile, hat, if, and qualifier blocks
References Find all uses of a variable (@{VAR}, ${VAR}) or profile (exec-transition and change_profile targets, signal/ptrace/peer=(label=…) peers) across open and indexed documents
Rename Rename a variable (@{VAR}) across all open and indexed documents; variables defined outside the workspace (e.g. @{HOME} from the system tunables) are not renamed
Selection Range Expand selection from rule → block → profile on each keypress

Requirements

The extension is a client for apparmor-language-server. Install the server before using this extension.

Install from snap (recommended)

sudo snap install apparmor-language-server

Install from PyPI

pip install apparmor-language-server

Install from source

git clone https://gitlab.com/apparmor/apparmor-language-server
cd apparmor-language-server
pip install .

Extension Settings

Setting Default Description
apparmor.serverPath "" Explicit path to the apparmor-language-server executable. Takes precedence over all other settings.
apparmor.pythonPath "" Path to a Python interpreter that has apparmor-language-server installed. Consulted when the server is not found on PATH.
apparmor.diagnostics.enable true Enable or disable all diagnostic checks.
apparmor.baseDir "" AppArmor base directory override (e.g. /var/lib/snapd/apparmor for snap). Leave empty for the system default (/etc/apparmor).
apparmor.includeSearchPaths [] Additional directories to search when resolving include directives.
apparmor.parserConfigFile "" Path to an apparmor_parser configuration file.
apparmor.apparmorParserPath "" Path to the apparmor_parser binary for syntax validation.
apparmor.auditLog.enable true Offer source code actions that add rules suggested by AppArmor denials recorded in the audit log.
apparmor.auditLog.path "" Audit log file to read denial events from. Leave empty to auto-detect (/var/log/audit/audit.log when readable, otherwise the systemd journal).
apparmor.codeLens.enable true Show code lenses (rule/hat counts on profile headers, variable reference counts, audit-log rule suggestions, and subsumed-rule cleanup actions).
apparmor.severityDbPath "" AppArmor severity database used to rank rule suggestions. Leave empty to use /etc/apparmor/severity.db.
apparmor.formatting.maxLineLength 100 Maximum line length before rules are wrapped. Set to 0 to disable.
apparmor.formatting.fileRuleStyle node-local Style for file rules: implicit (omit file keyword), explicit (include it), or node-local (preserve each rule's existing style).
apparmor.formatting.sortLists true Sort parenthesised permission and flag lists alphabetically.
apparmor.formatting.normalizeInclude true Rewrite legacy #include directives as include.
apparmor.formatting.maxBlankLines 1 Maximum consecutive blank lines to keep. Set to -1 to disable collapsing.
apparmor.abstractionSuggestions.enable true Suggest replacing inline rules with include <abstractions/…> when sufficient coverage is detected.
apparmor.abstractionSuggestions.coverageThreshold 0.85 Minimum fraction of abstraction rules that must already be present in the profile (as equivalent rules, neither broader nor narrower) before a suggestion is made.
apparmor.abstractionSuggestions.severityLimit 5 Maximum severity.db score (0–10) for any rule the abstraction would newly grant; abstractions that exceed this are not suggested.

Commands

Command Description
AppArmor: Restart Language Server Stop and restart the language server (useful after changing settings or reinstalling the server).

Language Detection

The extension activates for files under any apparmor.d/ directory (matching the pattern **/apparmor.d/**), which covers the standard system profile directory /etc/apparmor.d/ and snap equivalents.

For any other file (e.g. a profile with no extension outside apparmor.d/), set the language manually: click the language indicator in the VS Code status bar and select AppArmor.

Issues and Contributing

  • Bug reports / feature requests: GitLab issue tracker
  • Merge requests: GitLab project
  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft