Bug#880490: tor: Does not start when the AppArmor LSM is enabled but the apparmor package is not installed

2017-11-03 Thread intrigeri
Viktor Jägersküpper: > I confirm that with this change tor starts normally without apparmor > installed. Thanks a lot for testing & reporting back!

Bug#880490: tor: Does not start when the AppArmor LSM is enabled but the apparmor package is not installed

2017-11-03 Thread intrigeri
Hi Laurent, Laurent Bigonville: > My 2¢ here. Why is AppArmorProfile even needed here? Shouldn't apparmor > figureout > itself that it need to migrate to the system_tor domain(?)? Good question, glad you're asking! :) It's technically doable to have an AppArmor profile that will be applied to a

Bug#880490: tor: Does not start when the AppArmor LSM is enabled but the apparmor package is not installed

2017-11-01 Thread Viktor Jägersküpper
On Wed, 01 Nov 2017 08:04:37 +0100 intrig...@debian.org wrote: > So I propose we do this: > > --- a/debian/systemd/tor@default.service > +++ b/debian/systemd/tor@default.service > @@ -20,7 +20,7 @@ Restart=on-failure > LimitNOFILE=65536 > > # Hardening > -AppArmorProfile=system_tor > +AppArmor

Bug#880490: tor: Does not start when the AppArmor LSM is enabled but the apparmor package is not installed

2017-11-01 Thread Laurent Bigonville
On Wed, 01 Nov 2017 08:04:37 +0100 intrig...@debian.org wrote: > Hi, > > as reported on > https://lists.alioth.debian.org/pipermail/pkg-apparmor-team/2017-October/001895.html > Tor does not start when the AppArmor LSM is enabled (which is the > default in Linux on current sid) but the apparmor

Bug#880490: tor: Does not start when the AppArmor LSM is enabled but the apparmor package is not installed

2017-11-01 Thread intrigeri
Package: tor Version: 0.3.1.8-1 Severity: grave Tags: patch X-Debugs-Cc: pkg-appar...@lists.alioth.debian.org Hi, as reported on https://lists.alioth.debian.org/pipermail/pkg-apparmor-team/2017-October/001895.html Tor does not start when the AppArmor LSM is enabled (which is the default in Linux