/etc/apparmor.d/usr.sbin.charon-systemd is in charon-systemd 5.6.2-1ubuntu2.
This file is owned by root:root, with mode 0o644.
The actual contents of the file can be viewed below.
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 | # ------------------------------------------------------------------
#
#   Copyright (C) 2016 Canonical Ltd.
#
#   This program is free software; you can redistribute it and/or
#   modify it under the terms of version 2 of the GNU General Public
#   License published by the Free Software Foundation.
#
#   Author: Jonathan Davies <jonathan.davies@canonical.com>
#           Ryan Harper <ryan.harper@canonical.com>
#
# ------------------------------------------------------------------
#include <tunables/global>
/usr/sbin/charon-systemd flags=(complain,attach_disconnected) {
  #include <abstractions/base>
  #include <abstractions/nameservice>
  #include <abstractions/authentication>
  #include <abstractions/openssl>
  #include <abstractions/p11-kit>
  capability ipc_lock,
  capability net_admin,
  capability net_raw,
  # allow priv dropping (LP: #1333655)
  capability chown,
  capability setgid,
  capability setuid,
  # libcharon-extra-plugins: xauth-pam
  capability audit_write,
  # libstrongswan-standard-plugins: agent
  capability dac_override,
  capability net_admin,
  capability net_raw,
  network,
  network raw,
  /bin/dash                 rmPUx,
  # libchron-extra-plugins: kernel-libipsec
  /dev/net/tun              rw,
  /etc/ipsec.conf           r,
  /etc/ipsec.secrets        r,
  /etc/ipsec.*.secrets      r,
  /etc/ipsec.d/             r,
  /etc/ipsec.d/**           r,
  /etc/ipsec.d/crls/*       rw,
  /etc/opensc/opensc.conf   r,
  /etc/strongswan.conf      r,
  /etc/strongswan.d/        r,
  /etc/strongswan.d/**      r,
  /etc/tnc_config           r,
  /proc/sys/net/core/xfrm_acq_expires   w,
  /run/charon.*             rw,
  /run/pcscd/pcscd.comm     rw,
  /usr/lib/ipsec/charon     rmix,
  /usr/lib/ipsec/imcvs/     r,
  /usr/lib/ipsec/imcvs/**   rm,
  /usr/lib/*/opensc-pkcs11.so rm,
  /var/lib/strongswan/*     r,
  # Site-specific additions and overrides. See local/README for details.
  #include <local/usr.sbin.charon-systemd>
}
 |