[Kernel-packages] [Bug 796588] Re: Fine-grained network mediation

2019-07-24 Thread Brad Figg
** Tags added: cscc -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/796588 Title: Fine-grained network mediation Status in AppArmor: In Progress Status in apparmor package in Ubuntu:

[Kernel-packages] [Bug 796588] Re: Fine-grained network mediation

2018-11-14 Thread John Johansen
In 4.20 we landed some of the infrastructure to support this. Specifically secmark support was landed which provides the infrastructure needed for apparmor labels to interact with iptables and iptables to interact with apparmor. This isn't something generally available for use yet as it

[Kernel-packages] [Bug 796588] Re: Fine-grained network mediation

2018-09-12 Thread Joseph Salisbury
** Tags added: kernel-key -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/796588 Title: Fine-grained network mediation Status in AppArmor: In Progress Status in apparmor package in

Re: [Kernel-packages] [Bug 796588] Re: Fine-grained network mediation

2018-09-12 Thread Mark Shuttleworth
Fine-grained network security for snaps is going to be fantastic, but it's also a rich area, and when networking policy stuff is done simplistically it becomes awkward more than useful. I'd suggest that we start now working up detailed design on the topic, so that when we are ready to start

[Kernel-packages] [Bug 796588] Re: Fine-grained network mediation

2018-09-10 Thread John Johansen
No disagreement that this is a high priority item. There is some work around fine grained mediation happening but I am unsure when it will land. The problem is that this is not the only high priority item that needs to be addressed. Changing priority of these items can certainly be discussed

[Kernel-packages] [Bug 796588] Re: Fine-grained network mediation

2018-09-10 Thread Nicholas Zatkovich
More to the point, implementing this would give snaps the ability to add fine-grained network permissions for plugs, and this would suddenly make snaps a very attractive alternative to Docker images for server apps. I think this should be considered for priority. -- You received this bug

[Kernel-packages] [Bug 796588] Re: Fine-grained network mediation

2018-09-10 Thread Nicholas Zatkovich
I suppose it's time for the bi-annual nudge on this. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/796588 Title: Fine-grained network mediation Status in AppArmor: In Progress

[Kernel-packages] [Bug 796588] Re: Fine-grained network mediation

2016-07-28 Thread Jamie Strandboge
FYI, this is a requirement for snapd, but it was deprioritized in favor of namespace stacking in support of LXD, upstreaming and other work in support of snappy (eg, gsettings mediation). A lot of work was done to support this, but the soonest it would be delivered given current priorities is

[Kernel-packages] [Bug 796588] Re: Fine-grained network mediation

2015-02-12 Thread Alberto Salvia Novella
** Changed in: apparmor Status: In Progress = Confirmed ** Tags added: kernel-net -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/796588 Title: Fine-grained network mediation

[Kernel-packages] [Bug 796588] Re: Fine-grained network mediation

2015-02-12 Thread Jamie Strandboge
** Changed in: apparmor Status: Confirmed = In Progress -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/796588 Title: Fine-grained network mediation Status in AppArmor Linux

[Kernel-packages] [Bug 796588] Re: Fine-grained network mediation

2014-10-23 Thread Jamie Strandboge
** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in: linux (Ubuntu) Status: New = Triaged ** Changed in: apparmor (Ubuntu) Status: Confirmed = Triaged ** Changed in: linux (Ubuntu) Importance: Undecided = High ** Tags added: aa-kernel --