[Touch-packages] [Bug 1584069] Re: change_profile rules need a modifier to allow non-secureexec transitions

2017-01-10 Thread Christian Boltz
Fixed in AppArmor 2.11. ** Changed in: apparmor Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1584069 Title:

[Touch-packages] [Bug 1584069] Re: change_profile rules need a modifier to allow non-secureexec transitions

2016-09-07 Thread Tyler Hicks
This bug was fixed in Ubuntu 16.04 with apparmor 2.10.95-0ubuntu2.2 ** Changed in: apparmor (Ubuntu Xenial) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu.

[Touch-packages] [Bug 1584069] Re: change_profile rules need a modifier to allow non-secureexec transitions

2016-08-02 Thread Tyler Hicks
I've thoroughly tested apparmor 2.10.95-0ubuntu2.2 in xenial-proposed. I've verified that this bug is fixed (via the test in the Original Report section of the description and the newly added upstream automated tests) and I've also went through the AppArmor Test Plan (excluding the Ubuntu Touch

[Touch-packages] [Bug 1584069] Re: change_profile rules need a modifier to allow non-secureexec transitions

2016-08-02 Thread Tyler Hicks
** Description changed: [Impact] Applications which use libapparmor's aa_change_onexec() to set up an AppArmor profile transition across an upcoming exec() cannot pre- initialize the environment. This is caused by AppArmor unconditionally setting the AT_SECURE flag on the process,

[Touch-packages] [Bug 1584069] Re: change_profile rules need a modifier to allow non-secureexec transitions

2016-07-29 Thread Martin Pitt
Hello Tyler, or anyone else affected, Accepted apparmor into xenial-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.1 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See

[Touch-packages] [Bug 1584069] Re: change_profile rules need a modifier to allow non-secureexec transitions

2016-07-28 Thread Tyler Hicks
** Description changed: + [Impact] + + Applications which use libapparmor's aa_change_onexec() to set up an + AppArmor profile transition across an upcoming exec() cannot pre- + initialize the environment. This is caused by AppArmor unconditionally + setting the AT_SECURE flag on the process,

[Touch-packages] [Bug 1584069] Re: change_profile rules need a modifier to allow non-secureexec transitions

2016-07-28 Thread Tyler Hicks
** Also affects: apparmor (Ubuntu Xenial) Importance: Undecided Status: New ** Changed in: apparmor (Ubuntu Xenial) Importance: Undecided => High ** Changed in: apparmor (Ubuntu Xenial) Status: New => In Progress ** Changed in: apparmor (Ubuntu Xenial) Assignee:

[Touch-packages] [Bug 1584069] Re: change_profile rules need a modifier to allow non-secureexec transitions

2016-07-28 Thread Launchpad Bug Tracker
This bug was fixed in the package apparmor - 2.10.95-4ubuntu2 --- apparmor (2.10.95-4ubuntu2) yakkety; urgency=medium * Drop the following change now that click-apparmor has been updated: - Continue installing aa-exec into /usr/sbin/ for now since click-apparmor's

[Touch-packages] [Bug 1584069] Re: change_profile rules need a modifier to allow non-secureexec transitions

2016-07-20 Thread Launchpad Bug Tracker
** Branch linked: lp:~apparmor-dev/apparmor/apparmor-ubuntu-citrain -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1584069 Title: change_profile rules need a modifier to

[Touch-packages] [Bug 1584069] Re: change_profile rules need a modifier to allow non-secureexec transitions

2016-07-20 Thread Launchpad Bug Tracker
** Branch linked: lp:apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1584069 Title: change_profile rules need a modifier to allow non-secureexec transitions

[Touch-packages] [Bug 1584069] Re: change_profile rules need a modifier to allow non-secureexec transitions

2016-05-31 Thread Tyler Hicks
Fix committed as r3469 ** Changed in: apparmor Status: In Progress => Fix Committed ** Changed in: apparmor (Ubuntu) Status: Triaged => In Progress -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in

[Touch-packages] [Bug 1584069] Re: change_profile rules need a modifier to allow non-secureexec transitions

2016-05-25 Thread Tyler Hicks
Patches out for review on the list: https://lists.ubuntu.com/archives/apparmor/2016-May/009708.html -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1584069 Title:

[Touch-packages] [Bug 1584069] Re: change_profile rules need a modifier to allow non-secureexec transitions

2016-05-20 Thread Christian Boltz
The tools also need to be updated (as soon as we decided on the exact syntax etc.) ** Tags added: aa-tools -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1584069 Title:

[Touch-packages] [Bug 1584069] Re: change_profile rules need a modifier to allow non-secureexec transitions

2016-05-20 Thread Tyler Hicks
** Description changed: As it stands today, all exec transitions triggered by a change_profile rule cause the AT_SECURE flag in the auxiliary vector to be set due to the kernel function apparmor_bprm_secureexec() returning 1 while setting up the execution environment. This causes libc to

[Touch-packages] [Bug 1584069] Re: change_profile rules need a modifier to allow non-secureexec transitions

2016-05-20 Thread Tyler Hicks
** Tags added: aa-parser -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1584069 Title: change_profile rules need a modifier to allow non-secureexec transitions Status

[Touch-packages] [Bug 1584069] Re: change_profile rules need a modifier to allow non-secureexec transitions

2016-05-20 Thread Tyler Hicks
** Also affects: apparmor Importance: Undecided Status: New ** Changed in: apparmor Importance: Undecided => High ** Changed in: apparmor Status: New => In Progress ** Changed in: apparmor Assignee: (unassigned) => Tyler Hicks (tyhicks) ** Changed in: apparmor (Ubuntu)