{
    "mode": "man",
    "parameter": "aa-status",
    "section": "8",
    "url": "https://www.chedong.com/phpMan.php/man/aa-status/8/json",
    "generated": "2026-10-07T15:22:05Z",
    "synopsis": "aa-status [option]",
    "sections": {
        "NAME": {
            "content": "aa-status - display various information about the current AppArmor policy.\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "aa-status [option]\n",
            "subsections": []
        },
        "DESCRIPTION": {
            "content": "aa-status will report various aspects of the current state of AppArmor confinement. By\ndefault, it displays the same information as if the --verbose argument were given. A sample\nof what this looks like is:\n\napparmor module is loaded.\n110 profiles are loaded.\n102 profiles are in enforce mode.\n8 profiles are in complain mode.\nOut of 129 processes running:\n13 processes have profiles defined.\n8 processes have profiles in enforce mode.\n5 processes have profiles in complain mode.\n\nOther argument options are provided to report individual aspects, to support being used in\nscripts.\n",
            "subsections": []
        },
        "OPTIONS": {
            "content": "aa-status accepts only one argument at a time out of:\n",
            "subsections": [
                {
                    "name": "--enabled",
                    "content": "returns error code if AppArmor is not enabled.\n",
                    "long": "--enabled"
                },
                {
                    "name": "--profiled",
                    "content": "displays the number of loaded AppArmor policies.\n",
                    "long": "--profiled"
                },
                {
                    "name": "--enforced",
                    "content": "displays the number of loaded enforcing AppArmor policies.\n",
                    "long": "--enforced"
                },
                {
                    "name": "--complaining",
                    "content": "displays the number of loaded non-enforcing AppArmor policies.\n",
                    "long": "--complaining"
                },
                {
                    "name": "--kill",
                    "content": "displays  the number of loaded enforcing AppArmor policies that will kill tasks on policy\nviolations.\n",
                    "long": "--kill"
                },
                {
                    "name": "--prompt",
                    "content": "displays the number of loaded enforcing AppArmor policies,  with  fallback  to  userspace\nmediation.\n",
                    "long": "--prompt"
                },
                {
                    "name": "--special-unconfined",
                    "content": "displays  the  number  of  loaded non-enforcing AppArmor policies that are in the special\nunconfined mode.\n\n--process-mixed displays the number of processes confined by profile stacks with profiles in\ndifferent modes.",
                    "long": "--special-unconfined"
                },
                {
                    "name": "--verbose",
                    "content": "displays multiple data points about loaded AppArmor policy set (the default action if  no\narguments are given).\n",
                    "long": "--verbose"
                },
                {
                    "name": "--json",
                    "content": "displays  multiple data points about loaded AppArmor policy set in a JSON format, fit for\nmachine consumption.\n",
                    "long": "--json"
                },
                {
                    "name": "--pretty-json",
                    "content": "same as --json, formatted to be readable by humans as well as by machines.\n",
                    "long": "--pretty-json"
                },
                {
                    "name": "--show",
                    "content": "what data sets to show information about. Currently processes,  profiles,  all  for  both\nprocesses and profiles. The default is all.\n",
                    "long": "--show"
                },
                {
                    "name": "--count",
                    "content": "display only counts for selected information.\n\n--filter.mode=filter\nAllows  specifying  a  posix  regular  expression filter that will be applied against the\ndisplayed processess and profiles apparmor profile mode, reducing the output.\n\n--filter.profiles=filter\nAllows specifying a posix regular expression filter that  will  be  applied  against  the\ndisplayed processess and profiles confining profile, reducing the output.\n\n--filter.pid=filter\nAllows  specifying  a  posix  regular  expression filter that will be applied against the\ndisplayed processes, so  that  only  processes  pids  matching  the  expression  will  be\ndisplayed.\n\n--filter.exe=filter\nAllows  specifying  a  posix  regular  expression filter that will be applied against the\ndisplayed processes, so that only processes executable name matching the expression  will\nbe displayed.\n",
                    "long": "--count"
                },
                {
                    "name": "--help",
                    "content": "displays a short usage statement.\n",
                    "long": "--help"
                }
            ]
        },
        "EXIT STATUS": {
            "content": "Upon exiting, aa-status will set its exit status to the following values:\n\n0   if apparmor is enabled and policy is loaded.\n\n1   if apparmor is not enabled/loaded.\n\n2   if apparmor is enabled but no policy is loaded.\n\n3   if the apparmor control files aren't available under /sys/kernel/security/.\n\n4   if  the  user  running  the  script  doesn't  have enough privileges to read the apparmor\ncontrol files.\n\n42  if an internal error occurred.\n",
            "subsections": []
        },
        "BUGS": {
            "content": "aa-status must be run as root to read the state  of  the  loaded  policy  from  the  apparmor\nmodule.  It  uses  the  /proc  filesystem to determine which processes are confined and so is\nsusceptible to race conditions.\n\nIf     you     find     any     additional     bugs,     please      report      them      at\n<https://gitlab.com/apparmor/apparmor/-/issues>.\n",
            "subsections": []
        },
        "SEE ALSO": {
            "content": "apparmor(7), apparmor.d(5), and <https://wiki.apparmor.net>.\n\nAppArmor 4.0.1                               2026-04-13                                 AA-STATUS(8)",
            "subsections": []
        }
    },
    "summary": "aa-status - display various information about the current AppArmor policy.",
    "flags": [
        {
            "flag": "",
            "long": "--enabled",
            "arg": null,
            "description": "returns error code if AppArmor is not enabled."
        },
        {
            "flag": "",
            "long": "--profiled",
            "arg": null,
            "description": "displays the number of loaded AppArmor policies."
        },
        {
            "flag": "",
            "long": "--enforced",
            "arg": null,
            "description": "displays the number of loaded enforcing AppArmor policies."
        },
        {
            "flag": "",
            "long": "--complaining",
            "arg": null,
            "description": "displays the number of loaded non-enforcing AppArmor policies."
        },
        {
            "flag": "",
            "long": "--kill",
            "arg": null,
            "description": "displays the number of loaded enforcing AppArmor policies that will kill tasks on policy violations."
        },
        {
            "flag": "",
            "long": "--prompt",
            "arg": null,
            "description": "displays the number of loaded enforcing AppArmor policies, with fallback to userspace mediation."
        },
        {
            "flag": "",
            "long": "--special-unconfined",
            "arg": null,
            "description": "displays the number of loaded non-enforcing AppArmor policies that are in the special unconfined mode. --process-mixed displays the number of processes confined by profile stacks with profiles in different modes."
        },
        {
            "flag": "",
            "long": "--verbose",
            "arg": null,
            "description": "displays multiple data points about loaded AppArmor policy set (the default action if no arguments are given)."
        },
        {
            "flag": "",
            "long": "--json",
            "arg": null,
            "description": "displays multiple data points about loaded AppArmor policy set in a JSON format, fit for machine consumption."
        },
        {
            "flag": "",
            "long": "--pretty-json",
            "arg": null,
            "description": "same as --json, formatted to be readable by humans as well as by machines."
        },
        {
            "flag": "",
            "long": "--show",
            "arg": null,
            "description": "what data sets to show information about. Currently processes, profiles, all for both processes and profiles. The default is all."
        },
        {
            "flag": "",
            "long": "--count",
            "arg": null,
            "description": "display only counts for selected information. --filter.mode=filter Allows specifying a posix regular expression filter that will be applied against the displayed processess and profiles apparmor profile mode, reducing the output. --filter.profiles=filter Allows specifying a posix regular expression filter that will be applied against the displayed processess and profiles confining profile, reducing the output. --filter.pid=filter Allows specifying a posix regular expression filter that will be applied against the displayed processes, so that only processes pids matching the expression will be displayed. --filter.exe=filter Allows specifying a posix regular expression filter that will be applied against the displayed processes, so that only processes executable name matching the expression will be displayed."
        },
        {
            "flag": "",
            "long": "--help",
            "arg": null,
            "description": "displays a short usage statement."
        }
    ],
    "examples": [],
    "see_also": [
        {
            "name": "apparmor",
            "section": "7",
            "url": "https://www.chedong.com/phpMan.php/man/apparmor/7/json"
        },
        {
            "name": "apparmor.d",
            "section": "5",
            "url": "https://www.chedong.com/phpMan.php/man/apparmor.d/5/json"
        },
        {
            "name": "AA-STATUS",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/AA-STATUS/8/json"
        }
    ]
}