[Bug 2058690] Re: aa-easyprof: allow mmap and link from easyprof generated profiles

2024-05-01 Thread Ratchanan Srirattanamet
Hmm... indeed! I'll re-investigate why we need `m` permission by the default. I assume that if there's something that actually need `m` permission, a new key in the easyprof manifest would be needed, right? As for `l` rule for writes, do you think it's safe to add? Given that "the new link MUST

[Bug 2058690] Re: aa-easyprof: allow mmap and link from easyprof generated profiles

2024-04-19 Thread Seth Arnold
The 'm' permission shouldn't be a default; restricting what the CPU will execute is a very useful security mitigation. Thanks -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2058690 Title: