Package: ftp.debian.org Severity: normal X-Debbugs-Cc: [email protected], [email protected] Control: affects -1 + src:apparmor-profiles-extra User: [email protected] Usertags: remove Control: block -1 by 1147157 Control: block -1 by 1146674
Hi, First, for a variety of reasons, the preferred way to add AppArmor policy to Debian (short of having it maintained upstream) is to include it in the package that ships the confined software, so it can be tested together with software updates, and the maintainer is the best placed to tell whether a specific newly denied access is legitimate or not. So apparmor-profiles-extra was always meant to be a temporary hack. The amount of profiles shipped in that package has been decreasing a fair bit and we're now down to 2 profiles + 1 abstraction that's not used anywhere, except by fwknop-apparmor-profile (#1147157). Additionally, it's always been awkward to maintain the profiles shipped in this package, with no automated mechanism to track the multiple sources of input we use here. Finally, and this is the last nail in the coffin for me, the main source of AppArmor profiles for this is deprecated. Not only it was dormant since a year or 3, with no capacity available for reviewing fixes, but more recently the corresponding GitLab project was repurposed and does not include the profiles that we have in apparmor-profiles-extra anymore: https://lists.ubuntu.com/archives/apparmor/2026-August/014935.html Thanks!

