On 2016-05-29 03:52 PM, Christian Boltz wrote: >>> Do we need to explicitely "deny capability chown," in the profile? >> >> Since the original issue remains, I think it should be re-added [1]. > > Thanks, merged.
Thank you. >> In the meantime, you might want to try to the chroot feature :) >> >> chroot: "/var/lib/unbound" > > You probably know what happens if someone tells me "you might want to > try ...". If not, have a look at > https://bugzilla.opensuse.org/show_bug.cgi?id=982145 We've been through something similar on Debian/Ubuntu. The solution was to augment the init script to setup the chroot then pass the in-chroot path of the config file to unbound-checkconf. The Debian maintainer has written a helper script [1] to factor this out of the init script. Adding a "check_config" action to it would probably make it suitable for reuse in your systemd unit. Regards, Simon 1: https://anonscm.debian.org/cgit/pkg-dns/unbound.git/tree/debian/package-helper
signature.asc
Description: OpenPGP digital signature
-- AppArmor mailing list [email protected] Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/apparmor
