[Touch-packages] [Bug 1229066] Re: evince-thumbnailer can't run mktexpk

2014-10-09 Thread Jamie Strandboge
** Tags removed: apparmor ** Tags added: aa-policy -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1229066 Title: evince-thumbnailer can't run mktexpk Status in

[Touch-packages] [Bug 595714] Re: aa-status doesn't report an application as unconfined when using path globbing

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-tools -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/595714 Title: aa-status doesn't report an application as unconfined when using path globbing

[Touch-packages] [Bug 1070950] Re: /run/lxc/dnsmasq.pid denied by dnsmasq apparmor-profile

2014-10-09 Thread Jamie Strandboge
Is this still an issue on 14.10? ** Tags added: aa-policy ** Changed in: apparmor (Ubuntu) Status: Triaged = Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu.

[Touch-packages] [Bug 1192965] Re: user-mail abstraction refers to /var/spool/mail rather than /var/mail

2014-10-09 Thread Jamie Strandboge
Committed with r2742. ** Tags removed: apparmor ** Tags added: aa-policy -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1192965 Title: user-mail abstraction refers to

[Touch-packages] [Bug 1300948] Re: aa-genprof crashed with PermissionError in _mkstemp_inner(): [Errno 13] Permission denied: '/etc/apparmor.d/tmphtnhuikm~'

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-tools -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1300948 Title: aa-genprof crashed with PermissionError in _mkstemp_inner(): [Errno 13]

[Touch-packages] [Bug 1210514] Re: Default apache prefork profile doesn't allow chown

2014-10-09 Thread Jamie Strandboge
** Tags removed: policy ** Tags added: aa-policy -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1210514 Title: Default apache prefork profile doesn't allow chown Status

[Touch-packages] [Bug 512671] Re: usr/bin/man profile in ...doc...extra dir. in apparmor-profiles package is almost empty

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-policy -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/512671 Title: usr/bin/man profile in ...doc...extra dir. in apparmor-profiles package is almost

[Touch-packages] [Bug 1042771] Re: sanitized_helper prevents proper transition to other profiles

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-policy -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1042771 Title: sanitized_helper prevents proper transition to other profiles Status in

[Touch-packages] [Bug 1252904] Re: Move chromium-browser apparmor profile from apparmor package to c-b

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-policy -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1252904 Title: Move chromium-browser apparmor profile from apparmor package to c-b Status in

[Touch-packages] [Bug 1169568] Re: aa-unconfined does not always display unconfined processes with dual-stack

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-tools -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1169568 Title: aa-unconfined does not always display unconfined processes with dual- stack

[Touch-packages] [Bug 1304134] Re: aa-enforce crashed with apparmor.common.AppArmorException in store_list_var(): 'An existing variable redefined: @{TFTP_DIR}'

2014-10-09 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Status: New = Incomplete ** Tags added: aa-tools -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1304134 Title: aa-enforce

[Touch-packages] [Bug 850830] Re: aa-logprof updates standard profiles instead off changing local/profile

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-tools -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/850830 Title: aa-logprof updates standard profiles instead off changing local/profile Status in

[Touch-packages] [Bug 740510] Re: multiarch paths in abstractions should not be Linux-specific

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-policy -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/740510 Title: multiarch paths in abstractions should not be Linux-specific Status in “apparmor”

[Touch-packages] [Bug 545061] Re: Samba profile in Lucid prevents smbd from accessing /srv/samba

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-policy -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/545061 Title: Samba profile in Lucid prevents smbd from accessing /srv/samba Status in

[Touch-packages] [Bug 148984] Re: We should have Java and Mono abstractions

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-policy -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/148984 Title: We should have Java and Mono abstractions Status in “apparmor” package in Ubuntu:

[Touch-packages] [Bug 590636] Re: please include an apparmor profile for tinyproxy

2014-10-09 Thread Jamie Strandboge
** Tags removed: apparmor ** Tags added: aa-policy -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/590636 Title: please include an apparmor profile for tinyproxy Status

[Touch-packages] [Bug 811885] Re: AppArmor profile for Dropbox

2014-10-09 Thread Jamie Strandboge
** Tags removed: patch ** Tags added: aa-policy -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/811885 Title: AppArmor profile for Dropbox Status in “apparmor” package

[Touch-packages] [Bug 796588] Re: Limit inet and inet6 access by source or destination port

2014-10-09 Thread Jamie Strandboge
FYI, quite a bit more work was done on IPC in AppArmor, including the groundwork for fine-grained network mediation. Fine-grained network mediation will not land for 14.10, but may land in 15.04-15.10. ** Tags added: aa-feature ** Changed in: apparmor (Ubuntu) Importance: Wishlist = Medium

[Touch-packages] [Bug 387657] Re: aa-logprof: doesn't handle large logs

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-tools -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/387657 Title: aa-logprof: doesn't handle large logs Status in “apparmor” package in Ubuntu:

[Touch-packages] [Bug 511493] Re: Add Acrobat reader and flash restrictions

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-policy -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/511493 Title: Add Acrobat reader and flash restrictions Status in “apparmor” package in Ubuntu:

[Touch-packages] [Bug 571065] Re: asterisk apparmor profile

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-policy -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/571065 Title: asterisk apparmor profile Status in “apparmor” package in Ubuntu: Incomplete

[Touch-packages] [Bug 1378977] Re: /proc/sys/kernel/cap_last_cap denial for dnsmasq

2014-10-09 Thread Jamie Strandboge
This was fixed with r2735. ** Tags added: aa-policy -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1378977 Title: /proc/sys/kernel/cap_last_cap denial for dnsmasq

[Touch-packages] [Bug 914382] Re: Support oxygen gtk theme in abstractions/gnome

2014-10-09 Thread Jamie Strandboge
Is this patch still valid on 14.04 or 14.10? ** Tags added: aa-policy ** Changed in: apparmor (Ubuntu) Status: In Progress = Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu.

[Touch-packages] [Bug 1065390] Re: Please add /usr/bin/parole to the ubuntu-media-players abstraction

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-policy -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1065390 Title: Please add /usr/bin/parole to the ubuntu-media-players abstraction Status in

[Touch-packages] [Bug 970647] Re: Denials due to deleted are not being logged

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-feature ** Changed in: apparmor (Ubuntu) Status: New = Confirmed ** Changed in: linux Status: New = Confirmed ** Changed in: apparmor Status: New = Confirmed ** Changed in: apparmor Importance: Undecided = Low ** Changed in: apparmor (Ubuntu)

[Touch-packages] [Bug 1187447] Re: Please merge apparmor package descriptions from Debian

2014-10-09 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Importance: Undecided = Low ** Changed in: apparmor (Ubuntu) Status: Confirmed = Fix Committed ** Changed in: apparmor (Ubuntu) Assignee: (unassigned) = Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member

[Touch-packages] [Bug 1293525] Re: add apparmor profile for transmission-gtk

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-policy ** Changed in: apparmor (Ubuntu) Importance: Undecided = Low ** Changed in: transmission (Ubuntu) Importance: Undecided = Low -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in

[Touch-packages] [Bug 1310699] Re: package python3-apparmor (not installed) failed to install/upgrade: trying to overwrite '/usr/lib/python3/dist-packages/apparmor/__init__.py', which is also in packa

2014-10-09 Thread Jamie Strandboge
*** This bug is a duplicate of bug 1373259 *** https://bugs.launchpad.net/bugs/1373259 ** This bug has been marked a duplicate of bug 1373259 package python3-apparmor 2.8.95~2430-0ubuntu5 failed to install/upgrade: próba nadpisania /usr/lib/python3/dist-packages/apparmor/__init__.py,

[Touch-packages] [Bug 1354903] Re: Apparmor crashes when I create a new profile, with traceback

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-tools -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1354903 Title: Apparmor crashes when I create a new profile, with traceback Status in “apparmor”

[Touch-packages] [Bug 1347100] Re: package python3-apparmor 2.8.95~2430-0ubuntu5 failed to install/upgrade: trying to overwrite '/usr/lib/python3/dist-packages/apparmor/__init__.py', which is also in

2014-10-09 Thread Jamie Strandboge
*** This bug is a duplicate of bug 1373259 *** https://bugs.launchpad.net/bugs/1373259 ** This bug is no longer a duplicate of bug 1358637 package python3-apparmor 2.8.95~2430-0ubuntu5 failed to install/upgrade: trying to overwrite '/usr/lib/python3/dist-packages/apparmor/__init__.py',

[Touch-packages] [Bug 1373259] Re: package python3-apparmor 2.8.95~2430-0ubuntu5 failed to install/upgrade: próba nadpisania /usr/lib/python3/dist-packages/apparmor/__init__.py, który istnieje także

2014-10-09 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Status: Confirmed = In Progress ** Changed in: apparmor (Ubuntu) Importance: Undecided = High ** Changed in: apparmor (Ubuntu) Assignee: (unassigned) = Steve Beattie (sbeattie) ** Also affects: apparmor (Ubuntu Trusty) Importance: Undecided

[Touch-packages] [Bug 1324608] Re: when aa-logprof processed file access rules with mask of c the resulting profile doesn't work

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-tools -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1324608 Title: when aa-logprof processed file access rules with mask of c the resulting profile

[Touch-packages] [Bug 1358637] Re: package python3-apparmor 2.8.95~2430-0ubuntu5 failed to install/upgrade: trying to overwrite '/usr/lib/python3/dist-packages/apparmor/__init__.py', which is also in

2014-10-09 Thread Jamie Strandboge
*** This bug is a duplicate of bug 1373259 *** https://bugs.launchpad.net/bugs/1373259 ** This bug has been marked a duplicate of bug 1373259 package python3-apparmor 2.8.95~2430-0ubuntu5 failed to install/upgrade: próba nadpisania /usr/lib/python3/dist-packages/apparmor/__init__.py,

[Touch-packages] [Bug 1373259] Re: package python3-apparmor 2.8.95~2430-0ubuntu5 failed to install/upgrade: próba nadpisania /usr/lib/python3/dist-packages/apparmor/__init__.py, który istnieje także

2014-10-09 Thread Jamie Strandboge
** This bug is no longer a duplicate of bug 1358637 package python3-apparmor 2.8.95~2430-0ubuntu5 failed to install/upgrade: trying to overwrite '/usr/lib/python3/dist-packages/apparmor/__init__.py', which is also in package apparmor-utils 2.8.0-0ubuntu5 -- You received this bug

[Touch-packages] [Bug 1378977] Re: /proc/sys/kernel/cap_last_cap denial for dnsmasq

2014-10-09 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Status: Triaged = In Progress -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1378977 Title: /proc/sys/kernel/cap_last_cap denial

[Touch-packages] [Bug 1045985] Re: AppArmor should support environment filtering

2014-10-09 Thread Jamie Strandboge
** Tags added: aa-feature ** Changed in: apparmor (Ubuntu) Importance: High = Medium -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1045985 Title: AppArmor should

[Touch-packages] [Bug 914382] Re: Support oxygen gtk theme in abstractions/gnome

2014-10-09 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Importance: Undecided = Wishlist -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/914382 Title: Support oxygen gtk theme in

[Touch-packages] [Bug 1293439] Re: Apparmor prevents icedtea-7-plugin from creating necessary files

2014-10-09 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Status: Triaged = In Progress -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1293439 Title: Apparmor prevents icedtea-7-plugin

[Touch-packages] [Bug 1377140] Re: @{HOME}/.config/mimeapps.list missing in abstraction/freedesktop.org

2014-10-09 Thread Jamie Strandboge
Fixed in r2732 ** Changed in: apparmor (Ubuntu) Status: Triaged = In Progress -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1377140 Title:

[Touch-packages] [Bug 512671] Re: usr/bin/man profile in ...doc...extra dir. in apparmor-profiles package is almost empty

2014-10-09 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Importance: Low = Wishlist -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/512671 Title: usr/bin/man profile in ...doc...extra dir. in

[Touch-packages] [Bug 1293525] Re: add apparmor profile for transmission-gtk

2014-10-09 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Importance: Low = Wishlist ** Changed in: transmission (Ubuntu) Importance: Low = Wishlist -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu.

[Touch-packages] [Bug 796588] Re: Fine-grained network mediation

2014-10-09 Thread Jamie Strandboge
** Summary changed: - Limit inet and inet6 access by source or destination port + Fine-grained network mediation -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/796588

[Touch-packages] [Bug 969299] Re: apparmor prevents dpkg-divert and localedef from working in a container

2014-10-09 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Importance: Undecided = Medium -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/969299 Title: apparmor prevents dpkg-divert and

[Touch-packages] [Bug 665790] Re: apparmor initramfs script broken

2014-10-09 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Importance: Undecided = Medium -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/665790 Title: apparmor initramfs script broken Status

[Touch-packages] [Bug 1045985] Re: AppArmor should support environment filtering

2014-10-09 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Importance: Medium = Low -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1045985 Title: AppArmor should support environment filtering

[Touch-packages] [Bug 1370218] Re: confined applications need access to /run/shm/shmfd*

2014-10-09 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Importance: Medium = Low ** Summary changed: - confined applications need access to /run/shm/shmfd* + Fine-grained shm mediation (confined applications need access to /run/shm/shmfd*) -- You received this bug notification because you are a member of Ubuntu

[Touch-packages] [Bug 1306781] Re: Kernel to userspace communication is needed to notify trusted helpers of profile changes

2014-10-09 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Importance: Medium = Low ** Changed in: apparmor Importance: Medium = Low -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1306781

[Touch-packages] [Bug 1354903] Re: aa-genprof crashes when I create a new profile, with traceback

2014-10-09 Thread Jamie Strandboge
** Summary changed: - Apparmor crashes when I create a new profile, with traceback + aa-genprof crashes when I create a new profile, with traceback ** Changed in: apparmor (Ubuntu) Importance: Undecided = Medium -- You received this bug notification because you are a member of Ubuntu Touch

[Touch-packages] [Bug 1324608] Re: when aa-logprof processed file access rules with mask of c the resulting profile doesn't work

2014-10-09 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Importance: Undecided = Medium -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1324608 Title: when aa-logprof processed file access

[Touch-packages] [Bug 1197060] Re: SDK webview applications should use an app-specific path for shared memory files

2014-10-09 Thread Jamie Strandboge
The apparmor portion of this bug is being tracked in 1370218 ** Changed in: apparmor (Ubuntu) Status: In Progress = Won't Fix ** Changed in: apparmor (Ubuntu) Importance: Medium = Undecided -- You received this bug notification because you are a member of Ubuntu Touch seeded

[Touch-packages] [Bug 1379537] [NEW] Coarse-grained keyring mediation

2014-10-09 Thread Jamie Strandboge
Public bug reported: Tracking bug to support coarse-grained keyring mediation. ** Affects: apparmor (Ubuntu) Importance: High Assignee: Tyler Hicks (tyhicks) Status: Triaged ** Tags: aa-feature -- You received this bug notification because you are a member of Ubuntu Touch

[Touch-packages] [Bug 1379535] [NEW] namespace stacking

2014-10-09 Thread Jamie Strandboge
Public bug reported: Tracking bug for supporting stacked namesapaces (ie, different profiles on host, container, container in a container, etc) ** Affects: apparmor (Ubuntu) Importance: Critical Assignee: John Johansen (jjohansen) Status: In Progress ** Tags: aa-feature --

[Touch-packages] [Bug 1045985] Re: support environment filtering

2014-10-09 Thread Jamie Strandboge
** Summary changed: - AppArmor should support environment filtering + support environment filtering -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1045985 Title:

[Touch-packages] [Bug 1379536] [NEW] Coarse-grained keyring mediation

2014-10-09 Thread Jamie Strandboge
Public bug reported: Tracking bug to support coarse-grained keyring mediation. ** Affects: apparmor (Ubuntu) Importance: High Assignee: Tyler Hicks (tyhicks) Status: Triaged ** Tags: aa-feature -- You received this bug notification because you are a member of Ubuntu Touch

[Touch-packages] [Bug 484786] Re: Better support btrfs snapshots

2014-10-09 Thread Jamie Strandboge
** Summary changed: - Too easy to circumvent AppArmor using btrfs snapshots + Better support btrfs snapshots ** Changed in: apparmor (Ubuntu) Importance: Medium = Low -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

[Touch-packages] [Bug 1272028] Re: remount, not honored on bind mounts

2014-10-09 Thread Jamie Strandboge
** Also affects: apparmor (Ubuntu Utopic) Importance: Undecided Status: Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1272028 Title: remount, not

[Touch-packages] [Bug 1379541] [NEW] Named sockets should use 'unix' rules instead of 'file'

2014-10-09 Thread Jamie Strandboge
Public bug reported: Move to unix rules for named sockets. This solves a number of issues surrounding getopt, setopt and listen and removes an inconsistency in our policy. needs abi bump ** Affects: apparmor (Ubuntu) Importance: Low Status: Triaged ** Tags: aa-feature -- You

[Touch-packages] [Bug 1379542] [NEW] Better support systemd on Ubuntu

2014-10-09 Thread Jamie Strandboge
Public bug reported: Tracking bug for moving AppArmor to systemd in Ubuntu. ** Affects: apparmor (Ubuntu) Importance: Critical Status: Triaged ** Tags: aa-feature -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed

[Touch-packages] [Bug 1379538] [NEW] Better support docker.io

2014-10-09 Thread Jamie Strandboge
Public bug reported: This tracks the proper fix for bug #1371310. ** Affects: apparmor (Ubuntu) Importance: Low Status: Confirmed ** Tags: aa-feature -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor

[Touch-packages] [Bug 1379540] [NEW] Support policy versioning

2014-10-09 Thread Jamie Strandboge
Public bug reported: Tracking bug for policy versioning. ** Affects: apparmor (Ubuntu) Importance: Medium Status: Confirmed ** Tags: aa-feature -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in

[Touch-packages] [Bug 1379537] Re: Fine-grained keyring mediation

2014-10-09 Thread Jamie Strandboge
** Summary changed: - Coarse-grained keyring mediation + Fine-grained keyring mediation ** Changed in: apparmor (Ubuntu) Assignee: Tyler Hicks (tyhicks) = (unassigned) ** Changed in: apparmor (Ubuntu) Importance: High = Low ** Description changed: - Tracking bug to support

[Touch-packages] [Bug 1350598] Re: AppArmor policy compile improvements

2014-10-09 Thread Jamie Strandboge
** Also affects: click-apparmor (Ubuntu) Importance: Undecided Status: New ** Changed in: click-apparmor (Ubuntu) Status: New = Confirmed ** Changed in: click-apparmor (Ubuntu) Importance: Undecided = Critical -- You received this bug notification because you are a member

[Touch-packages] [Bug 1379536] Re: Coarse-grained kernel keyring mediation

2014-10-09 Thread Jamie Strandboge
** Summary changed: - Coarse-grained keyring mediation + Coarse-grained kernel keyring mediation ** Description changed: - Tracking bug to support coarse-grained keyring mediation. + Tracking bug to support coarse-grained kernel keyring mediation. ** Changed in: apparmor (Ubuntu)

[Touch-packages] [Bug 796588] Re: Fine-grained network mediation

2014-10-09 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Importance: Medium = High -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/796588 Title: Fine-grained network mediation Status in

[Touch-packages] [Bug 1357103] Re: apparmor denied a golang build inside a container

2014-10-10 Thread Jamie Strandboge
I'm going to mark as Fix Released for now then. Please open a new bug if you see this again. ** Changed in: linux (Ubuntu) Status: Incomplete = Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in

[Touch-packages] [Bug 545061] Re: Samba profile in Lucid prevents smbd from accessing /srv/samba

2014-10-10 Thread Jamie Strandboge
Ubuntu could consider something like this, possibly be updating the file in /etc/apparmor.d/local or a tunable. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/545061

[Touch-packages] [Bug 1386014] Re: travou

2014-10-31 Thread Jamie Strandboge
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to xorg in Ubuntu. https://bugs.launchpad.net/bugs/1386014 Title: travou Status in “xorg” package in Ubuntu: New

[Touch-packages] [Bug 1387712] Re: start up error

2014-10-31 Thread Jamie Strandboge
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to xorg in Ubuntu. https://bugs.launchpad.net/bugs/1387712 Title: start up error Status in “xorg” package in Ubuntu:

[Touch-packages] [Bug 1385418] Re: update for 15.04 frameworks

2014-11-03 Thread Jamie Strandboge
This was fixed with 1.3.0 in vivid. ** Changed in: apparmor-easyprof-ubuntu (Ubuntu) Status: Triaged = Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor-easyprof-ubuntu in Ubuntu.

[Touch-packages] [Bug 1384286] Re: add directory allowing scopes and apps to share data

2014-11-03 Thread Jamie Strandboge
Assigning to Michi only so he can comment on the proposed path. Please assign back to me if you agree. ** Description changed: - Summary says it all, just need to decide on the directory. + Summary says it all, just need to decide on the directory. I propose using this rule: + # Allow scopes

[Touch-packages] [Bug 1379836] Re: dialer and messaging app show unlocked pin as locked

2014-11-03 Thread Jamie Strandboge
FYI, on 14.09-proposed/mako, this seems to be fixed in r118, so I think all mako needs is a promoted image. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to indicator-network in Ubuntu. https://bugs.launchpad.net/bugs/1379836

[Touch-packages] [Bug 1260098] Re: oxide does not seem to honor TMPDIR-- requires read access to /tmp and /var/tmp

2014-11-03 Thread Jamie Strandboge
** Changed in: apparmor-easyprof-ubuntu (Ubuntu) Status: New = Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor-easyprof-ubuntu in Ubuntu. https://bugs.launchpad.net/bugs/1260098 Title: oxide does

[Touch-packages] [Bug 1319546] Re: Remove sync-monitor policy rules

2014-11-03 Thread Jamie Strandboge
Are these ready to be removed now? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor-easyprof-ubuntu in Ubuntu. https://bugs.launchpad.net/bugs/1319546 Title: Remove sync-monitor policy rules Status in Address Book

[Touch-packages] [Bug 1260103] Re: oxide should use an app-specific path for shared memory files

2014-11-03 Thread Jamie Strandboge
** Changed in: apparmor-easyprof-ubuntu (Ubuntu) Status: New = Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor-easyprof-ubuntu in Ubuntu. https://bugs.launchpad.net/bugs/1260103 Title: oxide

[Touch-packages] [Bug 1227824] Re: please add trust-store integration to e-d-s for calendar API

2014-11-03 Thread Jamie Strandboge
** Changed in: apparmor-easyprof-ubuntu (Ubuntu) Status: New = Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor-easyprof-ubuntu in Ubuntu. https://bugs.launchpad.net/bugs/1227824 Title: please add

[Touch-packages] [Bug 1271577] Re: handle duplicate policy groups better

2014-11-03 Thread Jamie Strandboge
** Changed in: click-apparmor (Ubuntu) Status: Triaged = In Progress ** Changed in: click-apparmor (Ubuntu) Assignee: (unassigned) = Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed

[Touch-packages] [Bug 1238007] Re: aa-clickhook -f does not properly consider changes to abstractions and #include directories

2014-11-03 Thread Jamie Strandboge
** Changed in: click-apparmor (Ubuntu) Status: Triaged = In Progress ** Changed in: click-apparmor (Ubuntu) Assignee: (unassigned) = Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed

[Touch-packages] [Bug 1384812] Re: should be able to specify multiple paths with aa-clickhook --include

2014-11-03 Thread Jamie Strandboge
** Changed in: click-apparmor (Ubuntu) Status: Triaged = In Progress ** Changed in: click-apparmor (Ubuntu) Assignee: (unassigned) = Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed

[Touch-packages] [Bug 1387409] Re: make adding new frameworks easier

2014-11-03 Thread Jamie Strandboge
** Changed in: click-apparmor (Ubuntu) Status: Triaged = In Progress ** Changed in: click-apparmor (Ubuntu) Assignee: (unassigned) = Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed

[Touch-packages] [Bug 1389239] Re: apparmor is uninstalled when deploying icehouse nova-compute on Precise

2014-11-04 Thread Jamie Strandboge
Seems like 1.2.2-0ubuntu13.1.6~cloud0 needs to adjust its Depends. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1389239 Title: apparmor is uninstalled when deploying

[Touch-packages] [Bug 1389792] [NEW] theme not found when using a user-defined theme

2014-11-05 Thread Jamie Strandboge
Public bug reported: This bugs makes it so that developers cannot update the theming, which can be pretty important for some people and also important for working around color scheme issues in the theming (I've filed other bugs on this). Attached is a very simple application that tries to define

[Touch-packages] [Bug 1389792] Re: theme not found when using a user-defined theme

2014-11-05 Thread Jamie Strandboge
** Description changed: + This bugs makes it so that developers cannot change the theming, which + can be pretty important for some people and also important for working + around color scheme issues in the theming (I've filed other bugs on + this). + Attached is a very simple application that

[Touch-packages] [Bug 1389792] Re: theme not found when using a user-defined theme

2014-11-05 Thread Jamie Strandboge
** Changed in: ubuntu-ui-toolkit (Ubuntu) Status: Confirmed = Triaged ** Changed in: ubuntu-ui-toolkit (Ubuntu) Importance: Undecided = High ** Tags added: ota-1 -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

[Touch-packages] [Bug 1389792] Re: theme not found when using a user-defined theme

2014-11-05 Thread Jamie Strandboge
** Also affects: ubuntu-ui-toolkit (Ubuntu RTM) Importance: Undecided Status: New ** Changed in: ubuntu-ui-toolkit (Ubuntu RTM) Status: New = Confirmed ** Changed in: ubuntu-ui-toolkit (Ubuntu) Status: Triaged = Confirmed ** Changed in: ubuntu-ui-toolkit (Ubuntu RTM)

[Touch-packages] [Bug 1387214] Re: file corruption on touch images in rw portions of the filesystem

2014-11-06 Thread Jamie Strandboge
** Tags added: rtm14 ** Package changed: linux (Ubuntu) = system-image (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to system-image in Ubuntu. https://bugs.launchpad.net/bugs/1387214 Title: file corruption on

[Touch-packages] [Bug 1387214] Re: file corruption on touch images in rw portions of the filesystem

2014-11-06 Thread Jamie Strandboge
Huge thanks to Colin (and apw) for this find. I want to state that this is a very real problem and not theoretical. I've seen it many times, it is triggerable with enough reboots, and it has been seen on krillin by non-developers (ie, just through normal reboots and system-image updates).

[Touch-packages] [Bug 1387214] Re: [TOPBLOCKER] file corruption on touch images in rw portions of the filesystem

2014-11-06 Thread Jamie Strandboge
FYI, unconfirmed report via ubuntu-phone@: Glad it isn't only me having this issue -- I have come across this issue twice and it's been files in /home/ getting corrupted. ** Description changed: Symptoms are that cache files in /var/cache/apparmor and profiles in /var/lib/apparmor/profiles

[Touch-packages] [Bug 1390592] Re: 'ptrace peer=@{profile_name}' does not work on 14.04 (at least) with docker

2014-11-10 Thread Jamie Strandboge
Per Tyler, this is fixed in r2456. In 14.04, add-decimal-interp.patch should be removed in favor of this patch. ** No longer affects: linux (Ubuntu) ** Also affects: apparmor (Ubuntu Trusty) Importance: Undecided Status: New ** Changed in: apparmor (Ubuntu) Status: Confirmed =

[Touch-packages] [Bug 1384286] Re: add directory allowing scopes and apps to share data

2014-11-11 Thread Jamie Strandboge
) Assignee: (unassigned) = Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor-easyprof-ubuntu in Ubuntu. https://bugs.launchpad.net/bugs/1384286 Title: add directory allowing scopes and apps

[Touch-packages] [Bug 1384286] Re: add directory allowing scopes and apps to share data

2014-11-11 Thread Jamie Strandboge
I've added a click-reviewers-tools task to handle this from the scopes confinement specification: Because scopes share application data with apps shipped in the same click, reviewers must be careful if the click package contains any permissions that triggers a manual review (permissions that pass

[Touch-packages] [Bug 1384286] Re: add directory allowing scopes and apps to share data

2014-11-11 Thread Jamie Strandboge
** Changed in: apparmor-easyprof-ubuntu (Ubuntu) Assignee: (unassigned) = Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor-easyprof-ubuntu in Ubuntu. https://bugs.launchpad.net/bugs

[Touch-packages] [Bug 1384286] Re: add directory allowing scopes and apps to share data

2014-11-11 Thread Jamie Strandboge
Actually, I think I'd prefer this, unless there is a really compelling otherwise (ie, read-only): # Allow scopes to share data with the app shipped in the same click owner @{HOME}/.local/share/@{APP_PKGNAME}/ r, owner @{HOME}/.local/share/@{APP_PKGNAME}/** mrkl, -- You received this bug

[Touch-packages] [Bug 1384286] Re: add directory allowing scopes and apps to share data

2014-11-12 Thread Jamie Strandboge
Michi, this is what is currently in the scopes network template as a writable directory: @{HOME}/.local/share/unity-scopes/leaf-net/@{APP_PKGNAME}/* this is the read-only directory I want to add to the scopes network template so scopes can surface data from the app:

[Touch-packages] [Bug 1391930] Re: Need a way for applications to ask permission to read/write in pictures/videos folders on SD card

2014-11-12 Thread Jamie Strandboge
: Undecided = High ** Changed in: apparmor-easyprof-ubuntu (Ubuntu) Status: New = Confirmed ** Changed in: apparmor-easyprof-ubuntu (Ubuntu) Assignee: (unassigned) = Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages

[Touch-packages] [Bug 1384286] Re: add directory allowing scopes and apps to share data

2014-11-12 Thread Jamie Strandboge
So, if I understand you correctly, you are saying that @{HOME}/.local/share/unity-scopes/leaf-net/@{APP_PKGNAME}/* is the writable cache directory for the scope (exactly as it is now), and @{HOME}/.local/share/@{APP_PKGNAME}/* is the readable directory where the scope can read data produced by the

[Touch-packages] [Bug 1391930] Re: Need a way for applications to ask permission to read/write in pictures/videos folders on SD card

2014-11-13 Thread Jamie Strandboge
** Changed in: apparmor-easyprof-ubuntu (Ubuntu) Importance: High = Wishlist ** Changed in: apparmor-easyprof-ubuntu (Ubuntu) Status: Confirmed = Triaged ** Also affects: apparmor-easyprof-ubuntu (Ubuntu Vivid) Importance: Wishlist Assignee: Jamie Strandboge (jdstrand

[Touch-packages] [Bug 1384286] Re: add directory allowing scopes and apps to share data

2014-11-13 Thread Jamie Strandboge
= In Progress ** Also affects: apparmor-easyprof-ubuntu (Ubuntu Vivid) Importance: High Assignee: Jamie Strandboge (jdstrand) Status: In Progress ** Also affects: click-reviewers-tools (Ubuntu Vivid) Importance: High Assignee: Jamie Strandboge (jdstrand) Status: In Progress

[Touch-packages] [Bug 1391930] Re: Need a way for applications to ask permission to read/write in pictures/videos folders on SD card

2014-11-13 Thread Jamie Strandboge
** Changed in: apparmor-easyprof-ubuntu (Ubuntu Utopic) Status: Triaged = In Progress ** Changed in: apparmor-easyprof-ubuntu (Ubuntu Vivid) Status: Triaged = In Progress -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is

[Touch-packages] [Bug 1384286] Re: add directory allowing scopes and apps to share data

2014-11-13 Thread Jamie Strandboge
** Changed in: apparmor-easyprof-ubuntu (Ubuntu RTM) Status: In Progress = New ** Changed in: apparmor-easyprof-ubuntu (Ubuntu RTM) Assignee: (unassigned) = Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages

[Touch-packages] [Bug 1391930] Re: Need a way for applications to ask permission to read/write in pictures/videos folders on SD card

2014-11-13 Thread Jamie Strandboge
Per discussions on ubuntu-phone@ (https://lists.launchpad.net/ubuntu- phone/msg10456.html), the directory structure for these global directories is: /media/$user/$label/Pictures /media/$user/$label/Music /media/$user/$label/Videos '$label' is confirmed to not allow '/' in the name. Because the

<    1   2   3   4   5   6   7   8   9   10   >