Re: [apparmor] AppArmor and kernel capabilities

2017-09-18 Thread John Johansen
On 09/18/2017 07:21 PM, linux maillist wrote: > > >>> This raises some questions to me. First, does dac_override honor the >>> folder permission rules within the profile? For example, if there is a >>> rule "/foo/** r," does dac_override this rule? >>> (...) >> So gpg was run as root and tried to

Re: [apparmor] AppArmor and kernel capabilities

2017-09-18 Thread linux maillist
>> This raises some questions to me. First, does dac_override honor the >> folder permission rules within the profile? For example, if there is a >> rule "/foo/** r," does dac_override this rule? >> (...) > So gpg was run as root and tried to read, write, or execute, a file > (or write to a direc

Re: [apparmor] AppArmor and kernel capabilities

2017-09-12 Thread Seth Arnold
Hello, On Tue, Sep 12, 2017 at 07:04:06PM +0200, linux maillist wrote: > I creates a profile for gpg and that profile requested now the > capability dac_override. > > This raises some questions to me. First, does dac_override honor the > folder permission rules within the profile? For example, if

[apparmor] AppArmor and kernel capabilities

2017-09-12 Thread linux maillist
Good day, I run AppArmor version 2.10.2 on a kernel 4.4 system. I creates a profile for gpg and that profile requested now the capability dac_override. This raises some questions to me. First, does dac_override honor the folder permission rules within the profile? For example, if there is a rule