Re: [apparmor] How does ALIAS work?

2020-01-11 Thread John Johansen
On 1/5/20 8:47 AM, J. R. Okajima wrote: > John Johansen: >> currently it works poorly. What it does it rule rewriting so that >> the leading elements of a rule "should" be replaced. > ::: >> It is possible to fix this, so that the compiler can do the rewrite >> against the generated state

Re: [apparmor] Patching a system profile for a specific user

2020-01-11 Thread azurit
Citát Sylvain Leroux : Thanks azur, On 11/01/2020 08:25, azu...@pobox.sk wrote: just put this in /etc/apparmor.d/local/usr.bin.thunderbird : owner @{HOME}/.signature.d/** r, My issue is I don't want to change the system configuration. This isnt' possible. That file is used to local

Re: [apparmor] wildcard syntax

2020-01-11 Thread John Johansen
On 1/10/20 9:38 PM, mailing list wrote: > Hi there, > > does AA understand the ? as a wildcard for single characters? > E.g. VirtualBox seems to want creating temporary files like > > $HOME/#45678361 > > These temp files always start with hash key symbol which may > additionally trouble AA

Re: [apparmor] Patching a system profile for a specific user

2020-01-11 Thread John Johansen
On 1/11/20 2:40 AM, azu...@pobox.sk wrote: > Citát Sylvain Leroux : > >> Thanks azur, >> >> On 11/01/2020 08:25, azu...@pobox.sk wrote: >>> just put this in /etc/apparmor.d/local/usr.bin.thunderbird : >>> owner @{HOME}/.signature.d/** r, >> >> >> My issue is I don't want to change the system

Re: [apparmor] Patching a system profile for a specific user

2020-01-11 Thread John Johansen
On 1/10/20 2:07 PM, Sylvain Leroux wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > > Hi everyone, > > I'm a seasoned Linux administrator but I have little prior experience > with AppArmor. FWIW, I already have asked this question on the > SuperUser StackExchange web site this

Re: [apparmor] Patching a system profile for a specific user

2020-01-11 Thread Sylvain Leroux
Thanks azur, On 11/01/2020 08:25, azu...@pobox.sk wrote: > just put this in /etc/apparmor.d/local/usr.bin.thunderbird : > owner @{HOME}/.signature.d/** r, My issue is I don't want to change the system configuration. I would like to grant the extra permission *only* for the user that needs it.

Re: [apparmor] wildcard syntax

2020-01-11 Thread mailing list
At 11.01.20 12:31 John Johansen told us: > On 1/10/20 9:38 PM, mailing list wrote: >> Hi there, >> >> does AA understand the ? as a wildcard for single characters? >> E.g. VirtualBox seems to want creating temporary files like >> >> $HOME/#45678361 >> (...) > > $HOME is not a valid apparmor path