[apparmor] [Bug 789409] Re: /proc/[PID]/attr/current overwrite Null pointer dereference

2012-02-07 Thread John Johansen
** Changed in: linux-ec2 (Ubuntu Lucid) Status: New => Invalid ** Changed in: linux-ec2 (Ubuntu Lucid) Importance: Undecided => Low ** Changed in: linux-ec2 (Ubuntu Precise) Status: New => Invalid ** Changed in: linux-ec2 (Ubuntu Precise) Importance: Undecided => Low ** Chan

Re: [apparmor] [PATCH 2/4] 0002-aa-easyprof-policy.patch

2012-02-07 Thread Christian Boltz
Hello, Am Dienstag, 7. Februar 2012 schrieb Jamie Strandboge: > On Tue, 2012-02-07 at 16:50 +0100, Christian Boltz wrote: > > Is the "l" permission really needed for /opt? > > Maybe? I thought it conceivable that applications might have their own > tmp directory in /opt which is why I added 'l'

Re: [apparmor] [PATCH 0/4] Add aa-easyprof command line utility

2012-02-07 Thread Cliffe
I am a proponent of the idea of policy templates. Please feel free to look through the FBAC-LSM policy abstractions for template ideas. FBAC-LSM (an experimental LSM and policy tools) does some simple analysis of the application to confine, then recommends abstractions and adapts them to the ap

Re: [apparmor] [PATCH 0/4] Add aa-easyprof command line utility

2012-02-07 Thread Jamie Strandboge
On Tue, 2012-02-07 at 08:50 -0600, Jamie Strandboge wrote: > This patchset is to accomplish the code portion of the > security-p-app-isolation blueprint. aa-easyprof is a standalone CLI > application which can also be imported into developer SDKs. From the man > page: I forgot to mention that I am

Re: [apparmor] [PATCH 4/4] 0004-aa-easyprof-makefile.patch: Makefile integration

2012-02-07 Thread Jamie Strandboge
On Tue, 2012-02-07 at 17:05 +0100, Christian Boltz wrote: > Hallo Leute, > > Am Dienstag, 7. Februar 2012 schrieb Jamie Strandboge: > > diff -Naurp -x .bzr -x common apparmor-trunk/utils/Makefile > > apparmor-trunk-easyprof/utils/Makefile > > --- apparmor-trunk/utils/Makefile 2011-12-13 17:

Re: [apparmor] [PATCH 2/4] 0002-aa-easyprof-policy.patch

2012-02-07 Thread Jamie Strandboge
On Tue, 2012-02-07 at 16:50 +0100, Christian Boltz wrote: > Hello, > > Am Dienstag, 7. Februar 2012 schrieb Jamie Strandboge: > > diff -Naurp -x .bzr -x common > > apparmor-trunk/utils/easyprof/policygroups/opt-application > > apparmor-trunk-easyprof/utils/easyprof/policygroups/opt-application >

Re: [apparmor] [PATCH 4/4] 0004-aa-easyprof-makefile.patch: Makefile integration

2012-02-07 Thread Christian Boltz
Hallo Leute, Am Dienstag, 7. Februar 2012 schrieb Jamie Strandboge: > diff -Naurp -x .bzr -x common apparmor-trunk/utils/Makefile > apparmor-trunk-easyprof/utils/Makefile > --- apparmor-trunk/utils/Makefile 2011-12-13 17:34:55.0 -0600 > +++ apparmor-trunk-easyprof/utils/Makefile

Re: [apparmor] [PATCH 2/4] 0002-aa-easyprof-policy.patch

2012-02-07 Thread Christian Boltz
Hello, Am Dienstag, 7. Februar 2012 schrieb Jamie Strandboge: > diff -Naurp -x .bzr -x common > apparmor-trunk/utils/easyprof/policygroups/opt-application > apparmor-trunk-easyprof/utils/easyprof/policygroups/opt-application > --- apparmor-trunk/utils/easyprof/policygroups/opt-application 1969-

[apparmor] [PATCH 4/4] 0004-aa-easyprof-makefile.patch: Makefile integration

2012-02-07 Thread Jamie Strandboge
On Tue, 2012-02-07 at 08:50 -0600, Jamie Strandboge wrote: > This patchset is to accomplish the code portion of the > security-p-app-isolation blueprint. aa-easyprof is a standalone CLI > application which can also be imported into developer SDKs. From the man > page: ... > * 0004-aa-easyprof-makef

[apparmor] [PATCH 3/4] 0003-aa-easyprof-unittests.patch

2012-02-07 Thread Jamie Strandboge
On Tue, 2012-02-07 at 08:50 -0600, Jamie Strandboge wrote: > This patchset is to accomplish the code portion of the > security-p-app-isolation blueprint. aa-easyprof is a standalone CLI > application which can also be imported into developer SDKs. From the man > page: ... > * 0003-aa-easyprof-unitt

[apparmor] [PATCH 2/4] 0002-aa-easyprof-policy.patch

2012-02-07 Thread Jamie Strandboge
On Tue, 2012-02-07 at 08:50 -0600, Jamie Strandboge wrote: > This patchset is to accomplish the code portion of the > security-p-app-isolation blueprint. aa-easyprof is a standalone CLI > application which can also be imported into developer SDKs. From the man > page: ... > * 0002-aa-easyprof-polic

[apparmor] [PATCH 1/4] 0001-aa-easyprof.patch

2012-02-07 Thread Jamie Strandboge
On Tue, 2012-02-07 at 08:50 -0600, Jamie Strandboge wrote: > This patchset is to accomplish the code portion of the > security-p-app-isolation blueprint. aa-easyprof is a standalone CLI > application which can also be imported into developer SDKs. From the man > page: ... > * 0001-aa-easyprof.patch

[apparmor] [PATCH 0/4] Add aa-easyprof command line utility

2012-02-07 Thread Jamie Strandboge
This patchset is to accomplish the code portion of the security-p-app-isolation blueprint. aa-easyprof is a standalone CLI application which can also be imported into developer SDKs. From the man page: "aa-easyprof provides an easy to use interface for AppArmor policy generation. aa-easyprof suppo