[apparmor] [PATCH 5/5] Revise dconf

2016-12-16 Thread John Johansen
--- libraries/libapparmor/include/sys/apparmor.h | 16 ++--- libraries/libapparmor/src/kernel.c | 95 +--- parser/dconf.cc | 78 +++ parser/dconf.h | 8 +-- parser/parser_lex.l

[apparmor] [PATCH 4/5] Add support for dconf confinement

2016-12-16 Thread John Johansen
--- libraries/libapparmor/include/sys/apparmor.h | 27 + libraries/libapparmor/src/kernel.c | 151 ++ libraries/libapparmor/src/libapparmor.map| 4 + parser/Makefile | 13 ++- parser/dconf.cc |

[apparmor] [PATCH 3/5] Make some parameters of parser interface constant

2016-12-16 Thread John Johansen
--- parser/parser_interface.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/parser/parser_interface.c b/parser/parser_interface.c index 5d9e0a0..00a81f2 100644 --- a/parser/parser_interface.c +++ b/parser/parser_interface.c @@ -250,7 +250,7 @@ static inline void sd_writ

[apparmor] [PATCH 2/5] Add base function to query generic label data under a, given key

2016-12-16 Thread John Johansen
--- libraries/libapparmor/doc/aa_query_label.pod | 6 ++ libraries/libapparmor/include/sys/apparmor.h | 19 libraries/libapparmor/src/kernel.c| 119 ++ libraries/libapparmor/src/libapparmor.map | 2 + libraries/libapparmor/swig/SWIG/libapparmor.

[apparmor] [PATCH 1/5] Split aa_query_label into a base aa_query_cmd and it, aa_query_label

2016-12-16 Thread John Johansen
Split the basic transaction file query out of aa_query_label so that it can be reused by other query types. Signed-off-by: John Johansen --- libraries/libapparmor/doc/aa_query_label.pod | 16 - libraries/libapparmor/include/sys/apparmor.h | 2 + libraries/libapparmor/src/kernel.c

Re: [apparmor] dconf patches

2016-12-16 Thread John Johansen
On 08/16/2016 04:17 AM, John Johansen wrote: > On 08/02/2016 04:32 PM, William Hua wrote: >> Hello, >> >> If I may, I'd like to revive the old dconf confinement patches that we >> started over a year ago, but were never merged. >> >> All necessary patches are attached, as well as an extra test pro

[apparmor] [Contd.] [profile] /etc/cron.daily/logrotate: a couple of DENIED messages.

2016-12-16 Thread daniel curtis
Hi Seth >> I also don't know what tools would exist in 12.04 LTS >> that would make it easier to investigate this issue (...) So I have to add '1' to the /sys/module/apparmor/parameters/logsyscall, right? OK, but in 12.04 LTS value for this one is: N [~]$ sudo cat /sys/module/apparmor/parameters