[Touch-packages] [Bug 1759346] Re: ix scrubs environment when it shouldn't when going through aa-exec

2018-03-29 Thread Jamie Strandboge
FYI, I clarified the description that the issue is for 'aa-exec', not everything. ** Description changed: - Somewhere between 3.13 and 4.4, the scrubbing behavior of ix changed. - For example, on Ubuntu 12.04 and 14.04 we have: + Somewhere between 3.13 and 4.4, the scrubbing behavior of ix for

[Touch-packages] [Bug 1759346] Re: ix scrubs environment when it shouldn't when going through aa-exec

2018-03-29 Thread Jamie Strandboge
These seem like counter arguments. On the one hand you seem to say that scrubbing is ok for ix and then change to suggest modifying ix to not scrub and introduce Ix. This bug is really about an inconsistency between 'ix' for normal fork/exec where there is no scrubbing and 'ix' on aa-exec where

[Touch-packages] [Bug 1759346] Re: ix scrubs environment when it shouldn't when going through aa-exec

2018-03-29 Thread Christian Boltz
Just wondering - if this bug survived so long without being noticed, isn't it a sign that in most cases scrubbing doesn't hurt or is even a good idea? Should we introduce Ix to officially have a way to inherit with scrubbing? -- You received this bug notification because you are a member of

[Touch-packages] [Bug 1759346] Re: ix scrubs environment when it shouldn't when going through aa-exec

2018-03-28 Thread Jamie Strandboge
FYI, this was discovered because of https://forum.snapcraft.io/t/2-0 -lxd-snap-fails-on-sytems-with-partial-apparmor-support/4707 ** Description changed: - Somewhere between 3.13 and 4.4, the scrubbing behavior of ix changed - when going through aa-exec. For example, on Ubuntu 12.04 and 14.04 we

[Touch-packages] [Bug 1759346] Re: ix scrubs environment when it shouldn't

2018-03-27 Thread Jamie Strandboge
Attached is an updated reproducer that adds 'aa-exec -p env -- ...' (ie, not unconfined). It operates the same (ie, ix still scrubs). ** Attachment added: "reproducer2.tar.gz" https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1759346/+attachment/5092826/+files/reproducer2.tar.gz **