[Bug 1377338] Re: apparmor may fail to load some profiles if one is corrupted

2022-02-13 Thread intrigeri
I'm a bit confused: * On the one hand, this bug is *not* marked is fixed in AppArmor upstream; the only reason it was marked as "Fix Released" for Ubuntu is the pile of kludges added in /lib/apparmor/functions, that I migrated to rc.apparmor.functions upstream a few years back. * On the other

[Bug 1379535] Re: policy namespace stacking

2022-02-12 Thread intrigeri
I see this is "Fix Released" everywhere but on the upstream AppArmor project. I understand this has made its way upstream and works with mainline kernel, e.g. for LXC. If my understanding is incorrect, please clarify what's left to do here (or perhaps track it on a finer-grained follow-up bug :)

[Bug 1384746] Re: Support multiple versions of AppArmor policy cache files

2022-02-12 Thread intrigeri
It seems to me this was fixed & released a while ago. https://bugs.launchpad.net/apparmor/+bug/1384746/comments/2 could be tracked on a new, follow-up bug, if still desired. ** Changed in: apparmor Status: In Progress => Fix Released -- You received this bug notification because you are

[Bug 1865519] Re: apparmor depends on python3

2022-02-12 Thread intrigeri
Fixed in 3.0.0 ** Changed in: apparmor Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1865519 Title: apparmor depends on python3 To manage

[Bug 387657] Re: aa-logprof: doesn't handle large logs

2022-02-12 Thread intrigeri
1.5 later with no feedback, let's assume the tentative fix works. ** Changed in: apparmor Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/387657 Title:

[Bug 1575438] Re: usr.sbin.nscd needs r/w access to nslcd socket

2022-02-12 Thread intrigeri
Fix released in 3.0.0. ** Changed in: apparmor Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1575438 Title: usr.sbin.nscd needs r/w access to nslcd

[Bug 1331856] Re: apparmor-utils don't work when defining a variable on

2022-02-12 Thread intrigeri
** Changed in: apparmor Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1331856 Title: apparmor-utils don't work when defining a variable on To manage

[Bug 1435452] Re: dh_apparmor has no dh sequencer support

2022-02-12 Thread intrigeri
** Bug watch added: Debian Bug tracker #934735 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=934735 ** Also affects: apparmor (Debian) via https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=934735 Importance: Unknown Status: Unknown -- You received this bug notification

Re: [Bug 1821920] Re: apparmor-profiles installs the chromium-browser profile but not the abstraction

2019-03-30 Thread intrigeri
Tyler Hicks: > It looks like the change mentioned in the above comment came from > Debian. Here's the commit: > https://salsa.debian.org/apparmor- > team/apparmor/commit/dc14f24b2c2943c29d0368f913020f1307d8f1d3 > They obviously don't have Actually, Debian has these abstractions and most of

[Bug 1117804] Re: ausearch doesn't show AppArmor denial messages

2018-12-16 Thread intrigeri
Meta: I've re-read the discussion from December 2017. If there were messages later than this on the thread, I missed them due to suboptimal mailing list archive presentation. Sorry if this leads me to wrong conclusions! I lack the skills to do the actual work I think should be done. The only way

[Bug 1784023] Re: Update profiles for usrmerge

2018-11-02 Thread intrigeri
I took a look because this appeared on the Debian package tracker for apparmor-profiles-extra. At least 1.24 (just uploaded to sid) seems to be OK. I've not checked older versions so I don't know when exactly the problem that affected this package (which seems unspecified here) was fixed. If

[Bug 1503762] Re: Provide systemd service

2018-03-19 Thread intrigeri
FTR a systemd unit was imported upstream: https://gitlab.com/apparmor/apparmor/merge_requests/81 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1503762 Title: Provide systemd service To manage

[Bug 1751402] Re: abstraction/nameservice should include allow access to /var/lib/sss/mc/initgroups

2018-02-25 Thread intrigeri
FTR this was already added upstream in commit 84cd523d8c which is part of AppArmor v2.12. So i'll be fixed whenever Ubuntu upgrades to 2.12 :) ** Also affects: apparmor Importance: Undecided Status: New ** Changed in: apparmor Status: New => Fix Released -- You received this

Re: [Bug 1284507] Re: apparmor profile for libreoffice

2018-01-16 Thread intrigeri
> This was partially done. unfortunately the profiles are all missing a / I think that's been fixed in Debian already. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1284507 Title: apparmor profile

Re: [Bug 1717714] Re: @{pid} variable broken on systems with pid_max more than 6 digits

2018-01-14 Thread intrigeri
Eric Desrochers: > The patch for bionic (devel release) has been sponsored but it is stuck in > bionic-proposed for now waiting for the non amd64/i386 builder to be > operational -> ppcel64, arm, s390x, .. FWIW this patch is part of 2.12-1 that I've uploaded to Debian unstable. No idea how

[Bug 1331856] Re: apparmor-utils don't work when defining a variable on

2018-01-07 Thread intrigeri
Vincas, do you want to test the proposed patch? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1331856 Title: apparmor-utils don't work when defining a variable on To manage notifications about

[Bug 1738958] Re: Ordering of start and apparmor reload upgrade can cause issues

2017-12-21 Thread intrigeri
Indeed, steps 3 and 4 should ideally happen in the reverse order. I don't know if debhelper provides facilities to order autoscript snippets though. In passing, once https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1385414 is done I think we should use systemd's AppArmorProfile= directive

[Bug 1579548] Re: OTR plugin does not load in Xenial

2017-12-12 Thread intrigeri
I guess this package needs the Ubuntu equivalent of what we call a binNMU in Debian. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1579548 Title: OTR plugin does not load in Xenial To manage

[Bug 1730536] Re: "Unable to open external link" in Evince when google-chrome-unstable is the default browser

2017-11-15 Thread intrigeri
** Changed in: apparmor Status: Confirmed => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1730536 Title: "Unable to open external link" in Evince when google-chrome-unstable

[Bug 1730536] Re: "Unable to open external link" in Evince when google-chrome-unstable is the default browser

2017-11-12 Thread intrigeri
https://gitlab.com/apparmor/apparmor/merge_requests/9 fixes this bug on my Debian sid test VM. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1730536 Title: "Unable to open external link" in Evince

[Bug 1730536] Re: "Unable to open external link" in evince

2017-11-12 Thread intrigeri
This should be easy to fix with something very similar to https://gitlab.com/apparmor/apparmor/merge_requests/7. While I'm at it I'll check that google-chrome-stable works too. ** Changed in: apparmor (Ubuntu) Status: New => Confirmed ** Also affects: apparmor Importance: Undecided

Re: [Bug 1721278] Re: apparmor="DENIED" operation="create" profile="/usr/sbin/cups-browsed" w/ 4.14-rc2 and later

2017-10-29 Thread intrigeri
> The kernel patch causing the issue has been reverted. So 4.14-rc7 should work as pre 4.14-rc2 Great! (Modulo Linus' commit messageā€¦) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1721278 Title:

[Bug 1042771] Re: sanitized_helper prevents proper transition to other profiles

2017-10-27 Thread intrigeri
See https://bugs.launchpad.net/apparmor-profiles/+bug/1727993 for a discussion about this topic. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1042771 Title: sanitized_helper prevents proper

Re: [Bug 1717714] [NEW] @{pid} variable broken on systems with pid_max more than 6 digits

2017-09-18 Thread intrigeri
> I am aware this is a non-default configuration, but I think this should work. Makes sense. Do you want to send a merge request? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1717714 Title:

[Bug 1710487] Re: evince silently crashes with apparmor error on artful

2017-09-10 Thread intrigeri
FWIW: Jamie, while reviewing the Debian..Ubuntu packaging log in order to merge the Ubuntu one into the Debian source package, I see a few instances of duplicate packaging work going on (e.g. the fix for this bug, upstart job removal). Such duplicate work could have been avoided by merging from

[Bug 1661766] Re: aa-genprof crashes on start due to python 3.6 bug

2017-09-10 Thread intrigeri
FTR Debian sid still defaults to python3 == Python 3.5, but will soon switch to 3.6 (https://release.debian.org/transitions/html/python3.6-supported.html) and will therefore be affected. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1117804] Re: ausearch doesn't show AppArmor denial messages

2017-09-03 Thread intrigeri
FTR this was raised as a potential blocker for enabling AppArmor by default on Debian: https://bugs.debian.org/872726. I'm going to investigate why this is a blocker there. tl;dr: as the audit maintainers said in 2014 (https://www.redhat.com/archives/linux-audit/2014-May/msg00119.html) and 2016

[Bug 1598759] Re: AppArmor nameservice abstraction doesn't allow communication with systemd-resolved

2017-08-05 Thread intrigeri
FWIW current Ubuntu citrain branch seems to apply exactly the same patch twice for some reason: debian/patches/adjust-nameservice-for-systemd-resolved.patch debian/patches/profiles-grant-access-to-systemd-resolved.patch Not sure what's going on, but anyway we don't apply this patch in Debian so

[Bug 1503762] Re: Provide systemd service

2017-08-04 Thread intrigeri
** Bug watch added: Debian Bug tracker #870697 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870697 ** Also affects: apparmor (Debian) via https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870697 Importance: Unknown Status: Unknown ** Also affects: apparmor (Ubuntu)

[Bug 1385414] Re: provide systemd compatible cache loading library

2017-07-01 Thread intrigeri
Thanks! So we still need an AppArmor task, not just a systemd one, right? (My question came up because all the AppArmor tasks are marked as "Fix released", and thus I thought the only remaining thing to do is on the systemd side, but your answer suggests that's not actually the case.) -- You

[Bug 1331856] Re: apparmor-utils don't work when defining a variable on

2017-06-30 Thread intrigeri
Anyone interested in moving this forward: please send a merge request. We're apparently not very good at tracking patches attached to bug reports, sorry! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1385414] Re: provide systemd compatible cache loading library

2017-06-30 Thread intrigeri
I could ask for help to the person who implemented the initial AppArmor support in systemd. But first I would need a clearer task description than "Add systemd task since it needs an update to make it use the cache loading library". What exactly do we need systemd to do? -- You received this bug

[Bug 1507469] Re: Evince's AppArmor profile prevents opening docs from other apps under Wayland

2017-06-30 Thread intrigeri
This was fixed in 2.11.0 so it's fixed in zesty. ** Summary changed: - Evince's Apparmour profile prevents opening docs from other apps under Wayland + Evince's AppArmor profile prevents opening docs from other apps under Wayland ** Changed in: apparmor (Ubuntu) Status: New => Fix

[Bug 740510] Re: multiarch paths in abstractions should not be Linux-specific

2017-06-30 Thread intrigeri
FWIW Stretch was released for Linux architectures only, and I doubt it'll change any time soon. I believe the Debian landscape looked different when Steve filed this bug in 2011. Nowadays I'm not sure what's the value of keeping this bug open. -- You received this bug notification because you

[Bug 776648] Re: apparmor profile for chromium browser

2017-06-30 Thread intrigeri
This bug report is about the custom profile shipped by Ubuntu in their apparmor-profiles package (and nowhere else AFAIK), not about the apparmor-profiles project (yeah, it's confusing, I know). ** Changed in: apparmor-profiles Status: Triaged => Invalid -- You received this bug

[Bug 1101298] Re: More resources must be added into Chromium profile

2017-06-30 Thread intrigeri
This bug report is about the custom profile shipped by Ubuntu in their apparmor-profiles package (and nowhere else AFAIK), not about the apparmor-profiles project (yeah, it's confusing, I know). ** Project changed: apparmor-profiles => apparmor (Ubuntu) -- You received this bug notification

[Bug 1647188] Re: Please make the AppArmor profile support merged-/usr systems

2017-01-06 Thread intrigeri
FYI I've applied this patch in the usr.sbin.tcpdump profile included in Debian's apparmor-profiles-extra 1.11. And I intend to have this profile moved to the tcpdump package proper at the beginning of the Debian 10 (Buster) development cycle, i.e. once Stretch is released. -- You received this

[Bug 1647188] Re: Please make the AppArmor profile support merged-/usr systems

2016-12-19 Thread intrigeri
Ping? Colder stages of the Debian Stretch freeze will soon be in effect, so it would be nice to have this reviewed & applied earlier :) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1647188 Title:

[Bug 1647188] [NEW] Please make the AppArmor profile support merged-/usr systems

2016-12-04 Thread intrigeri
Public bug reported: merged-/usr is already available in Debian, will likely be the default in Debian Stretch. The attached patch makes the included AppArmor profile support this use case. Thanks for considering :) ** Affects: tcpdump (Ubuntu) Importance: Undecided Status: New

[Bug 1507469] Re: Evince's Apparmour profile prevents opening docs from other apps under Wayland

2016-12-02 Thread intrigeri
Cherry-picked in Debian's Vcs-Bzr, will be part of the apparmor 2.10.95-7 upload. Thanks everybody! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1507469 Title: Evince's Apparmour profile prevents

Re: [Bug 1600524] Re: ubuntuBSD support

2016-07-16 Thread intrigeri
> Well then could you apply the patch to make apparmor installable? The dependency on any kind of initramfs-tools has been dropped in Debian a while ago (2.9.0-3+exp1), because AFAIK it was needed only for the early modules loading code, that was removed a while ago. For some undocumented reason,

Re: [Bug 1600524] Re: ubuntuBSD support

2016-07-16 Thread intrigeri
> I'm confused then. Why is the Architecture field in debian/control set to any? > And why debian/patches/non-linux.patch, debian/non- linux/apparmor_parser? I find it marginally useful to build on Debian/kFreeBSD: this can sometimes help discover real bugs that affect Linux but would not be

[Bug 1408106] Re: attach_disconnected not sufficient for overlayfs

2016-05-23 Thread intrigeri
Hi! What kind of (realistic) timeline can we expect here? (With the move to ZFS for containers, I wonder :) E.g. is this part of your goals for 16.10? (I mean: for the AppArmor /Ubuntu-specific parts, as I've learnt to be patient wrt. the upstreaming to Linux mainline.) Thanks for your work on

[Bug 1435368] Re: dh_apparmor does not assist postinst scripts that need to run the constrained binary before the postinst completes

2015-08-24 Thread intrigeri
Another workaround would be to run mysqld unconfined (e.g. with aa- unconfined, or by copying/hardlinking the binary to a different file and running that one) for whatever operations the postinst has to do. I won't pretend it's nicer than what you've done already, but that's another option on the

[Bug 1399845] Re: tunables/global doesn't include all defined variables

2015-08-24 Thread intrigeri
I'm not sure I get what's the problem: what exact variable (or tunable file containing variables) do you think should be made available to every profile, and is currently not? My understanding of this comment (as a non-native English speaker) is that there is a possibility that some tunables

[Bug 1377338] Re: apparmor may fail to load some profiles if one is corrupted

2015-08-24 Thread intrigeri
Along with LP: #1488179, this is one source of ugliness in current Debian/Ubuntu initscript, that makes it harder than needed to port it to systemd. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.