Bug#934869: [pkg-apparmor] Bug#934869: /etc/apparmor.d/usr.sbin.dnsmasq: profile doesn’t allow dnsmasq-base DNSSEC files

2020-05-25 Thread James Rowe
* intrigeri (intrig...@debian.org) wrote:
> Next time, please consider submitting your fixes directly there:
> taking me off the critical path would surely speed up the process
> considerably :)

  Thanks!  And sorry, I remember struggling a little with where and
against which package(apparmor/dnsmasq) to file the bug.  I'll Try
Harder™

Thanks,

James



Bug#934869: [pkg-apparmor] Bug#934869: /etc/apparmor.d/usr.sbin.dnsmasq: profile doesn’t allow dnsmasq-base DNSSEC files

2020-05-25 Thread intrigeri
Control: forwarded -1 https://gitlab.com/apparmor/apparmor/-/merge_requests/547

Hi,

James Rowe (2019-08-16):
>   If DNSSEC validation is enabled in the dnsmasq config file then the
> /usr/share/dnsmasq-base/trust-anchors.conf should be read by dnsmasq.
> However, the profile doesn’t allow access to it.
>
>   The following simple patch enables reading the DNS setup from
> dnsmasq-base:

Thank you.

I've forwarded this as a merge request upstream:
https://gitlab.com/apparmor/apparmor/-/merge_requests/547

I expect the fix will be part of the upstream 3.0 release.

Next time, please consider submitting your fixes directly there:
taking me off the critical path would surely speed up the process
considerably :)