Bug#923367: [pkg-apparmor] Bug#923367: AppArmor: Profile for journald

2019-03-07 Thread Seth Arnold
On Thu, Mar 07, 2019 at 09:41:40PM +0100, intrigeri wrote: > I would suggest trying to use the AppArmorProfile= directive in the > journald unit. I suspect it'll fail because some other stuff (normally > set up by apparmor.service) is not ready yet at the time journald > starts, but it'll be intere

Bug#923367: AppArmor: Profile for journald

2019-03-07 Thread Jörg Sommer
intrigeri hat am Do 07. Mär, 21:41 (+0100) geschrieben: > Jörg Sommer: > > But journald starts before the AppArmor profiles get loaded. > > I would suggest trying to use the AppArmorProfile= directive in the > journald unit. I suspect it'll fail because some other stuff (normally > set up by appar

Bug#923367: AppArmor: Profile for journald

2019-03-07 Thread intrigeri
Hi, [I thought I had sent this on Feb 27, it's in my Sent folder, but for some reason it did not make it to the BTS.] Jörg Sommer: > I've created a profile for journald to restrict the possible capabilities > the process has. Interesting! > But journald starts before the AppArmor profiles get l

Bug#923367: AppArmor: Profile for journald

2019-02-26 Thread Jörg Sommer
Package: apparmor-profiles Version: 2.13.2-9 Severity: normal Hi, I've created a profile for journald to restrict the possible capabilities the process has. But journald starts before the AppArmor profiles get loaded. I've created a service to run after apparmor.service to restart all unconfined