[Touch-packages] [Bug 1788929] Re: Debian/Ubuntu AppArmor policy for evince is useless

2018-09-29 Thread Jamie Strandboge
** Changed in: evince (Ubuntu Cosmic) Status: Triaged => Fix Committed ** Summary changed: - Debian/Ubuntu AppArmor policy for evince is useless + Debian/Ubuntu AppArmor policy gaps in evince ** Information type changed from Private Security to Public Security -- You received this bug

[Touch-packages] [Bug 1794848] Re: private-files-strict and user-files abstractions should also limit access to directories

2018-09-27 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu Cosmic) Status: In Progress => Fix Committed ** Changed in: apparmor (Ubuntu Trusty) Status: Triaged => In Progress ** Changed in: apparmor (Ubuntu Xenial) Status: Triaged => Fix Committed ** Changed in: apparmor (Ubuntu Bionic)

[Touch-packages] [Bug 1794848] Re: private-files-strict and user-files abstractions should also limit access to directories

2018-09-27 Thread Jamie Strandboge
https://gitlab.com/apparmor/apparmor/merge_requests/206/ has additional fixes. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1794848 Title: private-files-strict and

[Touch-packages] [Bug 1794848] Re: private-files-strict abstraction should also limit access to directories

2018-09-27 Thread Jamie Strandboge
https://gitlab.com/apparmor/apparmor/merge_requests/203/ was committed upstream. ** Changed in: apparmor Status: In Progress => Fix Released ** Summary changed: - private-files-strict abstraction should also limit access to directories + private-files-strict and user-files abstractions

[Touch-packages] [Bug 1794848] [NEW] private-files-strict abstraction should also limit access to directories

2018-09-27 Thread Jamie Strandboge
Public bug reported: This is to track the private-files-strict and user-files portion of https://bugs.launchpad.net/apparmor/+bug/1794820 ** Affects: apparmor Importance: Undecided Assignee: Jamie Strandboge (jdstrand) Status: Fix Released ** Affects: apparmor (Ubuntu

[Touch-packages] [Bug 1784937] Re: Add GRE protocol

2018-08-09 Thread Jamie Strandboge
I agree with Laurent - ufw already supports gre, gufw just needs to bubble that up. ** Package changed: ufw (Ubuntu) => gui-ufw -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to ufw in Ubuntu.

[Touch-packages] [Bug 1612393] Re: mount -> @{HOME}/... denial

2018-08-02 Thread Jamie Strandboge
rks +   mount -> /home/*/mnt/, This doesn't: - mount -> @{HOME}/mnt/, +   mount -> @{HOME}/mnt/, audit: type=1400 audit(1470943929.750:482): apparmor="DENIED" operation="mount" info="failed mntpnt match" error=-13 profile="test" nam

[Touch-packages] [Bug 1612393] Re: mount -> @{HOME}/... denial

2018-08-02 Thread Jamie Strandboge
/home/*/mnt/, This doesn't: mount -> @{HOME}/mnt/, audit: type=1400 audit(1470943929.750:482): apparmor="DENIED" operation="mount" info="failed mntpnt match" error=-13 profile="test" name="/home/jamie/mnt/" pid=25573 comm="fuse

[Touch-packages] [Bug 1204579] Re: ufw doesn't support concurrent updates

2018-07-17 Thread Jamie Strandboge
This is in git master now and in the ufw snap in candidate. ** Changed in: ufw Status: Triaged => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to ufw in Ubuntu. https://bugs.launchpad.net/bugs/1204579

[Touch-packages] [Bug 1781986] Re: package ufw 0.35-5 failed to install/upgrade: los disparadores han entrado en bucle, abandonando

2018-07-17 Thread Jamie Strandboge
** Package changed: ufw (Ubuntu) => hplip (Ubuntu) ** Changed in: hplip (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to ufw in Ubuntu. https://bugs.launchpad.net/bugs/1781986

[Touch-packages] [Bug 1781428] Re: pulseaudio built with --enable-snappy but 'Enable Snappy support: no'

2018-07-13 Thread Jamie Strandboge
We can't just enable the patches any more because it will change how snaps that plugs 'pulseaudio' will work. Put concretely, the patches are meant to detect if the connecting process is a snap and if it is, unconditionally deny recording. Some snaps that 'plugs: [ pulseaudio ]' have legitimate

[Touch-packages] [Bug 1781428] [NEW] pulseaudio built with --enable-snappy but 'Enable Snappy support: no'

2018-07-12 Thread Jamie Strandboge
Public bug reported: >From https://launchpadlibrarian.net/377100864/buildlog_ubuntu-cosmic- amd64.pulseaudio_1%3A12.0-1ubuntu1_BUILDING.txt.gz: ... dh_auto_configure -- --enable-x11 --disable-hal-compat --libdir=\${prefix}/lib/x86_64-linux-gnu

[Touch-packages] [Bug 951317] Re: ufw crashed with UnicodeDecodeError in get_loglevel(): 'ascii' codec can't decode byte 0xd0 in position 0: ordinal not in range(128)

2018-06-11 Thread Jamie Strandboge
*** This bug is a duplicate of bug 953372 *** https://bugs.launchpad.net/bugs/953372 @fathi733-gmail - this should've been fixed a long time ago. Anything you see now should be a new bug. Can you file one at https://bugs.launchpad.net/ufw/+filebug? -- You received this bug notification

[Touch-packages] [Bug 1775043] Re: bash completion not working: uses deprecated have()

2018-06-09 Thread Jamie Strandboge
ned) => Jamie Strandboge (jdstrand) ** Also affects: ufw (Ubuntu Cosmic) Importance: Undecided Status: New ** Also affects: ufw (Ubuntu Bionic) Importance: Undecided Status: New ** Changed in: ufw (Ubuntu Bionic) Status: New => Triaged ** Changed in: ufw (Ubun

[Touch-packages] [Bug 1726856] Re: ufw does not start automatically at boot

2018-05-29 Thread Jamie Strandboge
ke exactly what we should be doing. Thanks for the triage! ** Changed in: ufw (Ubuntu) Status: New => Triaged ** Changed in: ufw (Ubuntu) Assignee: (unassigned) => Jamie Strandboge (jdstrand) ** Also affects: ufw (Ubuntu Bionic) Importance: Undecided Status: New ** A

[Touch-packages] [Bug 1773515] Re: apparmour fails after removal of snapd

2018-05-29 Thread Jamie Strandboge
** Package changed: apparmor (Ubuntu) => snapd (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1773515 Title: apparmour fails after removal of snapd Status in

[Touch-packages] [Bug 1767880] Re: apparmor prevents Chromium (snap) to run the 2nd time

2018-04-30 Thread Jamie Strandboge
Note that this is for the chromium snap and it is the snapd package that provides the apparmor policy for the chromium snap. Also, the bluez accesses should not be what is preventing the chromium snap from starting-- these are harmless denials. I've adjusted the title of the to reflect this.

[Touch-packages] [Bug 1767164] Re: Apparmor removed on 16.04 LTS -> 18.04 upgrade

2018-04-26 Thread Jamie Strandboge
I tried to reproduce this and was unable to. The apparmor package did added a Breaks: media-hub, mediascanner2.0, messaging-app, webbrowser- app because of bug #1756800 and bug #1761176 so I tried upgrades with and without these installed. Test configurations: * Ubuntu Desktop default install *

[Touch-packages] [Bug 1767164] Re: Apparmor removed on 16.04 LTS -> 18.04 upgrade

2018-04-26 Thread Jamie Strandboge
Looking at https://github.com/lxc/lxd/issues/4504#issuecomment-384759354, it seems that the system may not have had ubuntu-standard installed, so on do- release-upgrade the final package removal step may have listed apparmor. -- You received this bug notification because you are a member of

[Touch-packages] [Bug 1712044] Re: AppArmor profile misses entries

2018-04-24 Thread Jamie Strandboge
This should be fixed in Ubuntu 18.04 (about to be released this week). ** Package changed: chromium-browser (Ubuntu) => apparmor (Ubuntu) ** Changed in: apparmor (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded

[Touch-packages] [Bug 1766600] Re: [bionic] apparmor denial for rsyslog modules in multiarch directory and pidfile

2018-04-24 Thread Jamie Strandboge
** Changed in: rsyslog (Ubuntu) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to rsyslog in Ubuntu. https://bugs.launchpad.net/bugs/1766600 Title: [bionic] apparmor denial for

[Touch-packages] [Bug 1766600] [NEW] [bionic] apparmor denial for rsyslog modules in multiarch directory and pidfile

2018-04-24 Thread Jamie Strandboge
uot; fsuid=0 ouid=0 So we need to adjust this: /{,var/}run/rsyslogd.pid rwk, to be: /{,var/}run/rsyslogd.pid{,.tmp} rwk, ** Affects: rsyslog (Ubuntu) Importance: High Assignee: Jamie Strandboge (jdstrand) Status: In Progress ** Description changed: With the new b

[Touch-packages] [Bug 1766600] Re: [bionic] apparmor denial for rsyslog modules in multiarch directory and pidfile

2018-04-24 Thread Jamie Strandboge
** Description changed: With the new bionic upload, when the apparmor profile is enabled, - rsyslog fails to start (and cause upgrade issues) due to: + rsyslog fails to start (and causes upgrade issues) due to: AVC apparmor="DENIED" operation="file_mmap" profile="/usr/sbin/rsyslogd"

[Touch-packages] [Bug 1766600] Re: [bionic] apparmor denial for rsyslog modules in multiarch directory

2018-04-24 Thread Jamie Strandboge
** Description changed: With the new bionic upload, when the apparmor profile is enabled, rsyslog fails to start (and cause upgrade issues) due to: AVC apparmor="DENIED" operation="file_mmap" profile="/usr/sbin/rsyslogd" name="/usr/lib/x86_64-linux-gnu/rsyslog/lmnet.so" pid=19949

[Touch-packages] [Bug 1712039] Re: AppArmor profile misses entry for /var/lib/snapd/desktop/applications/mimeinfo.cache

2018-04-18 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1712039 Title: AppArmor profile misses entry

[Touch-packages] [Bug 1762983] Re: communitheme snap doesn't work with evince

2018-04-18 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1762983 Title: communitheme snap doesn't work

[Touch-packages] [Bug 1701297] Re: NTP reload failure (unable to read library) on overlayfs

2018-04-17 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Status: Confirmed => Invalid -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1701297 Title: NTP reload failure (unable to read

[Touch-packages] [Bug 1712039] Re: AppArmor profile misses entry for /var/lib/snapd/desktop/applications/mimeinfo.cache

2018-04-17 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Status: Confirmed => In Progress -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1712039 Title: AppArmor profile misses entry for

[Touch-packages] [Bug 1752806] Re: package apparmor 2.10.95-0ubuntu2.9 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29

2018-04-17 Thread Jamie Strandboge
This looks like it might have been a transient file system issue. Is your system still in this state? If so, please run afilesystem check and then run 'sudo dpkg --configure -a ; sudo apt-get update ; sudo apt-get upgrade'. ** Changed in: apparmor (Ubuntu) Status: New => Incomplete --

[Touch-packages] [Bug 1734461] Re: laptop boots, post messages scoll up screen, and FAILED in red appears. cannot restart the saervice

2018-04-17 Thread Jamie Strandboge
*** This bug is a duplicate of bug 1756800 *** https://bugs.launchpad.net/bugs/1756800 This is almost certainly a duplicate of LP: #1756800. Please take a look at that bug and remove the affected profiles. Do note that apparmor is a oneshot service and it will report an error if any profiles

[Touch-packages] [Bug 1762983] Re: communitheme snap doesn't work with evince

2018-04-17 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Status: Confirmed => In Progress -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1762983 Title: communitheme snap doesn't work

[Touch-packages] [Bug 1757256] Re: Apparmor profile gajim

2018-04-17 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1757256 Title: Apparmor profile gajim Status in

[Touch-packages] [Bug 1764312] Re: fails to start in Bionic

2018-04-17 Thread Jamie Strandboge
The initial report indicated a parser error, but then it was reported that the apparmor package was removed, so then it would not be able to run properly. I'm not able to reproduce with the information given. If you are able to provide exact steps to reproduce, please do and we can take another

[Touch-packages] [Bug 1730908] Re: [ 1549.847151] audit: type=1400 audit(1510129355.497:61): apparmor="DENIED" operation="file_mmap" profile="/usr/bin/evince" name="/usr/lib/x86_64-linux-gnu/libproxy/

2018-04-17 Thread Jamie Strandboge
Does evince not work or is this simply a noisy denial? ** Changed in: apparmor (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu.

[Touch-packages] [Bug 1745872] Re: package libapparmor-perl 2.10.95-0ubuntu2.6 failed to install/upgrade: package libapparmor-perl is not ready for configuration cannot configure (current status 'half

2018-04-17 Thread Jamie Strandboge
There is not enough information to process this bug report. Is your system still in this state? Do you have steps to reproduce? ** Changed in: apparmor (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which

[Touch-packages] [Bug 1741673] Re: package apparmor 2.10.95-0ubuntu2.7 failed to install/upgrade: pakket verkeert in een heel slechte en inconsistente staat; u zou het opnieuw moeten installeren alvo

2018-04-17 Thread Jamie Strandboge
There is not enough information to process this bug. Is your system still in this state? Do you have steps to reproduce? ** Changed in: apparmor (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is

[Touch-packages] [Bug 1718841] Re: package libapparmor1:amd64 2.10.95-0ubuntu2.7 failed to install/upgrade: package libapparmor1:amd64 is not ready for configuration cannot configure (current status '

2018-04-17 Thread Jamie Strandboge
There is not enough information to process this bug report. Is your system still in this state? Do you have steps to reproduce? ** Changed in: apparmor (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which

[Touch-packages] [Bug 1704681] Re: package python3-apparmor 2.10.95-0ubuntu2.6 failed to install/upgrade

2018-04-17 Thread Jamie Strandboge
There is not enough information to process this bug. Is your system still affected? Do you have specific steps on how to reproduce? ** Changed in: apparmor (Ubuntu) Status: Confirmed => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded

[Touch-packages] [Bug 1704516] Re: package apparmor 2.10.95-0ubuntu2 failed to install/upgrade: 现在尚不能配置软件包 apparmor 不能配置(目前状态为 half-installed )

2018-04-17 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1704516 Title: package apparmor 2.10.95-0ubuntu2 failed

[Touch-packages] [Bug 1681515] Re: package dh-apparmor 2.9.1-0ubuntu9 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting configuration

2018-04-17 Thread Jamie Strandboge
There isn't enough information to process this bug. Is your system still affected? Can you provide steps to reproduce? ** Changed in: apparmor (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is

[Touch-packages] [Bug 1739943] Re: apparmor ntpd profile problem [64238.000768] audit: type=1400 audit(1513904231.500:45): apparmor="DENIED" operation="sendmsg" info="Failed name lookup - disconnected

2018-04-17 Thread Jamie Strandboge
The profile needs attach_disconnected. ** Package changed: apparmor (Ubuntu) => ntp (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to ntp in Ubuntu. https://bugs.launchpad.net/bugs/1739943 Title: apparmor ntpd

[Touch-packages] [Bug 1738155] Re: Calling reboot or poweroff on a node-red snap is fail

2018-04-17 Thread Jamie Strandboge
Did you use 'snap connect' to connect the shutdown interface? ** Package changed: apparmor (Ubuntu) => snapd (Ubuntu) ** Changed in: snapd (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is

[Touch-packages] [Bug 1693953] Re: package apparmor 2.10.95-0ubuntu2.6 failed to install/upgrade: 子进程 已安装 post-installation 脚本 返回错误状态 1

2018-04-17 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1693953 Title: package apparmor 2.10.95-0ubuntu2.6

[Touch-packages] [Bug 1756800] Re: Failed to start AppArmor initialization with status=123/n/a

2018-04-04 Thread Jamie Strandboge
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1761176 filed for messaging-app. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1756800 Title: Failed to start

[Touch-packages] [Bug 1761176] Re: remove one more old Touch profile that causes profile compilation errors

2018-04-04 Thread Jamie Strandboge
** Summary changed: - remove more old Touch profiles that cause profile compilation errors + remove one more old Touch profile that causes profile compilation errors ** Changed in: apparmor (Ubuntu) Status: In Progress => Fix Committed -- You received this bug notification because you

[Touch-packages] [Bug 1761176] [NEW] remove more old Touch profiles that cause profile compilation errors

2018-04-04 Thread Jamie Strandboge
Public bug reported: This is an extension of https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1756800 where we missed messaging-app. ** Affects: apparmor (Ubuntu) Importance: Undecided Assignee: Jamie Strandboge (jdstrand) Status: In Progress ** Description changed

[Touch-packages] [Bug 1756800] Re: Failed to start AppArmor initialization with status=123/n/a

2018-04-04 Thread Jamie Strandboge
Actually, only messaging-app is affected by this bug, so we don't need to remove the other two. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1756800 Title: Failed to

[Touch-packages] [Bug 1756800] Re: Failed to start AppArmor initialization with status=123/n/a

2018-04-04 Thread Jamie Strandboge
"Do we need to worry about: ubuntu-download-manager: /etc/apparmor.d/usr.lib.ubuntu-download-manager.udm-extractor messaging-app: /etc/apparmor.d/usr.bin.messaging-app content-hub-testability: /etc/apparmor.d/content-hub-testability " Yes. I did an archive grep and found media-hub, but that

[Touch-packages] [Bug 1756800] Re: Failed to start AppArmor initialization with status=123/n/a

2018-04-03 Thread Jamie Strandboge
Uploaded 2.12-4ubuntu3 to address this. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1756800 Title: Failed to start AppArmor initialization with status=123/n/a Status

[Touch-packages] [Bug 1756800] Re: Failed to start AppArmor initialization with status=123/n/a

2018-04-03 Thread Jamie Strandboge
media-hub is another application that was removed in bionic that is affected. ** Changed in: apparmor (Ubuntu) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu.

[Touch-packages] [Bug 1753966] Re: apparmor interfers with saving of PDF from evince

2018-04-03 Thread Jamie Strandboge
** Package changed: apparmor (Ubuntu) => evince (Ubuntu) ** Tags added: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1753966 Title: apparmor interfers with

[Touch-packages] [Bug 1756800] Re: Failed to start AppArmor initialization with status=123/n/a

2018-04-03 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Status: Won't Fix => In Progress ** Changed in: apparmor (Ubuntu) Assignee: (unassigned) => Jamie Strandboge (jdstrand) ** Changed in: ubuntu-release-upgrader (Ubuntu) Status: Confirmed => Won't Fix -- You received this bug not

[Touch-packages] [Bug 1759346] Re: ix scrubs environment when it shouldn't when going through aa-exec

2018-03-29 Thread Jamie Strandboge
FYI, I clarified the description that the issue is for 'aa-exec', not everything. ** Description changed: - Somewhere between 3.13 and 4.4, the scrubbing behavior of ix changed. - For example, on Ubuntu 12.04 and 14.04 we have: + Somewhere between 3.13 and 4.4, the scrubbing behavior of ix for

[Touch-packages] [Bug 1759346] Re: ix scrubs environment when it shouldn't when going through aa-exec

2018-03-29 Thread Jamie Strandboge
These seem like counter arguments. On the one hand you seem to say that scrubbing is ok for ix and then change to suggest modifying ix to not scrub and introduce Ix. This bug is really about an inconsistency between 'ix' for normal fork/exec where there is no scrubbing and 'ix' on aa-exec where

[Touch-packages] [Bug 1759769] Re: Failed to start AppArmor initialization.

2018-03-29 Thread Jamie Strandboge
*** This bug is a duplicate of bug 1756800 *** https://bugs.launchpad.net/bugs/1756800 ** This bug has been marked a duplicate of bug 1756800 Failed to start AppArmor initialization with status=123/n/a -- You received this bug notification because you are a member of Ubuntu Touch seeded

[Touch-packages] [Bug 1759346] Re: ix scrubs environment when it shouldn't when going through aa-exec

2018-03-28 Thread Jamie Strandboge
FYI, this was discovered because of https://forum.snapcraft.io/t/2-0 -lxd-snap-fails-on-sytems-with-partial-apparmor-support/4707 ** Description changed: - Somewhere between 3.13 and 4.4, the scrubbing behavior of ix changed - when going through aa-exec. For example, on Ubuntu 12.04 and 14.04 we

[Touch-packages] [Bug 1759346] Re: ix scrubs environment when it shouldn't

2018-03-27 Thread Jamie Strandboge
Attached is an updated reproducer that adds 'aa-exec -p env -- ...' (ie, not unconfined). It operates the same (ie, ix still scrubs). ** Attachment added: "reproducer2.tar.gz" https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1759346/+attachment/5092826/+files/reproducer2.tar.gz **

[Touch-packages] [Bug 1759346] [NEW] ix scrubs environment when it shouldn't

2018-03-27 Thread Jamie Strandboge
Public bug reported: Somewhere between 3.13 and 4.4, the scrubbing behavior of ix changed. For example, on Ubuntu 12.04 and 14.04 we have: * ux does not scrub * Ux does scrub * ix does not scrub but in 16.04 and later we have: * ux does not scrub * Ux does scrub * ix does scrub # WRONG I

[Touch-packages] [Bug 1747333] Re: unsafe hardlink restrictions deny lease backup

2018-03-27 Thread Jamie Strandboge
/usr.sbin.dhcpd # vim:syntax=apparmor # Last Modified: Mon Jan 25 11:06:45 2016 # Author: Jamie Strandboge <ja...@canonical.com> #include /usr/sbin/dhcpd flags=(complain) { #include #include #include capability chown, capability net_bind_service, capab

[Touch-packages] [Bug 1759032] Re: drop no longer needed 'capability sys_module' rule

2018-03-26 Thread Jamie Strandboge
** Changed in: isc-dhcp (Ubuntu) Status: In Progress => Fix Committed ** Changed in: isc-dhcp (Ubuntu) Assignee: (unassigned) => Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed

[Touch-packages] [Bug 1759032] [NEW] drop no longer needed 'capability sys_module' rule

2018-03-26 Thread Jamie Strandboge
Public bug reported: When the dhclient profile was written, net_admin hadn't yet allowed loading network modules. For some time it has though (https://lwn.net/Articles/430462/) and since the dhclient profile already allows 'net_admin', we should drop 'sys_module' from the profile. ** Affects:

[Touch-packages] [Bug 1758449] Re: skype snap does not work when home directory is not located in /home

2018-03-26 Thread Jamie Strandboge
*** This bug is a duplicate of bug 1620771 *** https://bugs.launchpad.net/bugs/1620771 This is a known issue. Please see: * https://forum.snapcraft.io/t/how-can-i-use-snap-when-i-dont-use-home-user/3352 * https://bugs.launchpad.net/snapcraft/+bug/1620771 ** Package changed: apparmor

[Touch-packages] [Bug 1756800] Re: Failed to start AppArmor initialization with status=123/n/a

2018-03-20 Thread Jamie Strandboge
This isn't really a bug in apparmor-- the profiles weren't purged from the system. We could perhaps add a Conflicts on webbrowser-app mediascanner2.0 to apparmor, but that doesn't feel right (and wouldn't remove the conffiles anyway (so this bug would remain)). Perhaps ubuntu- release-upgrader

[Touch-packages] [Bug 1756800] Re: Failed to start AppArmor initialization with status=123/n/a

2018-03-20 Thread Jamie Strandboge
No, the script is returning non-zero because some of the profiles didn't load, but the rest of the profiles will load fine. You can prove this to yourself using 'sudo aa-status'. As for those two profiles, the come from https://launchpad.net/ubuntu/+source/webbrowser-app/ and

[Touch-packages] [Bug 1567597] Re: implement 'complain mode' in seccomp for developer mode with snaps

2018-03-05 Thread Jamie Strandboge
This is fixed in xenial 2.3.1-2.1ubuntu2~16.04.1 ** Changed in: libseccomp (Ubuntu Xenial) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to libseccomp in Ubuntu.

[Touch-packages] [Bug 1751667] Re: classic snap does not run on live session

2018-03-02 Thread Jamie Strandboge
This is now merged in 2.32. Please see https://forum.snapcraft.io/t /confined-snaps-dont-work-on-live-images-due-to-apparmor-path- mapping/3767/9 if you want to check it out for yourself. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is

[Touch-packages] [Bug 1751667] Re: classic snap does not run on live session

2018-03-01 Thread Jamie Strandboge
/snap- confine and then loads all the /etc/apparmor.d/*snap-confine* profiles. So long as snapd starts before preinstalled snaps then all is fine. ** Changed in: apparmor (Ubuntu) Status: Confirmed => Invalid ** Changed in: apparmor (Ubuntu) Assignee: Jamie Strandboge (jdstr

[Touch-packages] [Bug 1751667] Re: classic snap does not run on live session

2018-03-01 Thread Jamie Strandboge
: apparmor (Ubuntu) Importance: Undecided Status: New ** No longer affects: ubiquity (Ubuntu) ** Changed in: apparmor (Ubuntu) Status: New => Triaged ** Changed in: apparmor (Ubuntu) Assignee: (unassigned) => Jamie Strandboge (jdstrand) ** Changed in: apparmor (

[Touch-packages] [Bug 1746463] Re: apparmor profile load in stacked policy container fails

2018-02-27 Thread Jamie Strandboge
FYI, the following kernels are also affected (all 4.13 based): * linux-azure * linux-hwe * linux-hwe-edge * linux-oem * linux-raspi2 -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu.

[Touch-packages] [Bug 1746463] Re: apparmor profile load in stacked policy container fails

2018-02-27 Thread Jamie Strandboge
Here are more details on the snapd test failure: https://forum.snapcraft.io/t/lxd-issue-due-to-snap-confine-apparmor- profile/4203/18 ** Also affects: snapd Importance: Undecided Status: New ** Changed in: snapd Status: New => Triaged -- You received this bug notification

[Touch-packages] [Bug 1746463] Re: apparmor profile load in stacked policy container fails

2018-02-27 Thread Jamie Strandboge
Since this is going to be fixed in 'linux' and 'linux-gcp', adding tasks for those. ** Changed in: apparmor (Ubuntu Artful) Status: Won't Fix => Fix Committed ** Changed in: linux (Ubuntu Artful) Status: Fix Committed => Confirmed ** Also affects: linux-gcp (Ubuntu) Importance:

[Touch-packages] [Bug 1746463] Re: apparmor profile load in stacked policy container fails

2018-02-27 Thread Jamie Strandboge
Add a snapd task so that when the https://launchpad.net/ubuntu/+source /linux-gcp is Fix Released, snapd can re-enable the tests/main/lxd test on GCE. ** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in: linux (Ubuntu Artful) Status: New => Fix

[Touch-packages] [Bug 1746463] Re: apparmor profile load in stacked policy container fails

2018-02-27 Thread Jamie Strandboge
This is affected snapd spread tests in GCE, where they have a xenial userspace and 4.13 kernel: # cat /proc/version_signature Ubuntu 4.13.0-1011.15-gcp 4.13.13 -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in

[Touch-packages] [Bug 1751762] Re: AppArmor prevents opening LibreOffice Writer documents from another HDD

2018-02-26 Thread Jamie Strandboge
*** This bug is a duplicate of bug 1751005 *** https://bugs.launchpad.net/bugs/1751005 ** Package changed: apparmor (Ubuntu) => libreoffice (Ubuntu) ** This bug has been marked a duplicate of bug 1751005 libreoffice cannot open a document not within $HOME -- You received this bug

[Touch-packages] [Bug 1670408] Re: apparmor base abstraction needs backport of rev 3658 to fix several denies (tor, ntp, ...)

2018-02-20 Thread Jamie Strandboge
This is fine for SRU. Thanks! -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1670408 Title: apparmor base abstraction needs backport of rev 3658 to fix several denies

[Touch-packages] [Bug 1750005] Re: Please remove in bionic

2018-02-16 Thread Jamie Strandboge
emove [y|N]? y 1 package successfully removed. ** Changed in: apparmor-easyprof-ubuntu (Ubuntu) Status: New => Fix Released ** Changed in: apparmor-easyprof-ubuntu (Ubuntu) Assignee: (unassigned) => Jamie Strandboge (jdstrand) -- You received this bug notification because

[Touch-packages] [Bug 1750005] [NEW] Please remove in bionic

2018-02-16 Thread Jamie Strandboge
: Undecided Assignee: Jamie Strandboge (jdstrand) Status: Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor-easyprof-ubuntu in Ubuntu. https://bugs.launchpad.net/bugs/1750005 Title: Please remove

[Touch-packages] [Bug 1733700] Re: python tools do not understand 'non-magic' include rules

2018-02-15 Thread Jamie Strandboge
(Ubuntu Bionic) Assignee: Jamie Strandboge (jdstrand) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1733700 Title: python tools do not understand '

[Touch-packages] [Bug 1370218] Re: Fine-grained shm mediation (confined applications need access to /run/shm/shmfd*)

2018-02-06 Thread Jamie Strandboge
** Changed in: qtbase-opensource-src (Ubuntu) Status: New => Won't Fix ** Changed in: qtmultimedia-opensource-src (Ubuntu) Status: New => Won't Fix -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

[Touch-packages] [Bug 1710637] Re: Input falls through to gdm3 and terminates the session on Ctrl+C after udevadm trigger is executed under wayland

2018-02-04 Thread Jamie Hutber
Would be great to get this fixed in 16.04 also guys -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to systemd in Ubuntu. https://bugs.launchpad.net/bugs/1710637 Title: Input falls through to gdm3 and terminates the session

[Touch-packages] [Bug 1713710] Re: RM: obsolete product

2018-01-31 Thread Jamie Strandboge
Thanks! :) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to click-apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1713710 Title: RM: obsolete product Status in click-apparmor package in Ubuntu: Fix Released Bug

[Touch-packages] [Bug 1746012] [NEW] please disable xconsole configuration in 50-default.conf to fix "rsyslogd-2007: action 'action 10' suspended, next retry is ..."

2018-01-29 Thread Jamie Strandboge
Public bug reported: I've noticed this for a long time but never looked into it. My logs have a bunch of entries of the form: rsyslogd-2007: action 'action 10' suspended, next retry is Mon Jan 29 04:08:13 2018 [v8.16.0 try http://www.rsyslog.com/e/2007 ] This is caused by these lines in

[Touch-packages] [Bug 1733700] Re: python tools do not understand 'non-magic' include rules

2018-01-05 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu Artful) Status: Triaged => In Progress ** Changed in: apparmor (Ubuntu Xenial) Status: Triaged => In Progress ** Changed in: apparmor (Ubuntu Trusty) Status: Triaged => In Progress -- You received this bug notification because you are a

[Touch-packages] [Bug 1733700] Re: python tools do not understand 'non-magic' include rules

2018-01-05 Thread Jamie Strandboge
** Description changed: The apparmor parser supports 'include' and '#include' rules for specifying absolute paths, but the python tools only understand include rules for so called 'magic' '<>' file locations. = test case #0 (testsuite) = $ sudo apt-get install apparmor apparmor-utils

[Touch-packages] [Bug 1733700] Re: python tools do not understand 'non-magic' include rules

2018-01-05 Thread Jamie Strandboge
** Description changed: The apparmor parser supports 'include' and '#include' rules for specifying absolute paths, but the python tools only understand include rules for so called 'magic' '<>' file locations. = test case #0 (testsuite) = - $ sudo apt-get install apparmor apparmor-utils

[Touch-packages] [Bug 1733700] Re: python tools do not understand 'non-magic' include rules

2018-01-04 Thread Jamie Strandboge
** Description changed: The apparmor parser supports 'include' and '#include' rules for specifying absolute paths, but the python tools only understand include rules for so called 'magic' '<>' file locations. + = test case #0 (testsuite) = + $ sudo apt-get install apparmor apparmor-utils

[Touch-packages] [Bug 1733700] Re: python tools do not understand 'non-magic' include rules

2018-01-04 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu Trusty) Assignee: (unassigned) => Jamie Strandboge (jdstrand) ** Changed in: apparmor (Ubuntu Xenial) Assignee: (unassigned) => Jamie Strandboge (jdstrand) ** Changed in: apparmor (Ubuntu Zesty) Assignee: (unassigned) => Jamie Strandboge

[Touch-packages] [Bug 1733700] Re: python tools do not understand 'non-magic' include rules

2018-01-04 Thread Jamie Strandboge
The was fixed upstream in 2.12. ** Changed in: apparmor Status: In Progress => Fix Released ** Changed in: apparmor (Ubuntu Bionic) Status: Triaged => In Progress ** Changed in: apparmor (Ubuntu Bionic) Assignee: (unassigned) => Jamie Strandboge (jdstrand) -- You

[Touch-packages] [Bug 1511439] Re: webbrowser-app apparmor policy fails to load on desktop

2018-01-03 Thread Jamie Strandboge
@Martin, do note that the apparmor policy should have been loaded for everything except webbrowser-app, but because there was a failure systemctl will show it as failed. Can you file a bug here: https://bugs.launchpad.net/ubuntu/+source/webbrowser-app/+filebug? This is a bug in the packaging for

[Touch-packages] [Bug 1733700] Re: python tools do not understand 'non-magic' include rules

2017-12-20 Thread Jamie Strandboge
** Description changed: The apparmor parser supports 'include' and '#include' rules for specifying absolute paths, but the python tools only understand include rules for so called 'magic' '<>' file locations. - Reproducer: - + + = test case #1 (aa-enforce) = $ mkdir /tmp/test1

[Touch-packages] [Bug 1733700] Re: python tools do not understand 'non-magic' include rules

2017-12-18 Thread Jamie Strandboge
** Description changed: - The apparmor_parser now supports 'include' rules in addition to - '#include', but the python tools only understand '#include'. This - manifested itself in Ubuntu in bug #1734038 (see - https://bugs.launchpad.net/ubuntu/+source/snapd/+bug/1734038/comments/15 - of that bug

[Touch-packages] [Bug 1733700] Re: python tools do not understand 'non-magic' include rules

2017-12-18 Thread Jamie Strandboge
** Summary changed: - apparmor python tools do not understand 'include' rules + python tools do not understand 'non-magic' include rules ** Changed in: apparmor (Ubuntu Trusty) Status: New => Triaged ** Changed in: apparmor (Ubuntu Xenial) Status: New => Triaged ** Changed in:

[Touch-packages] [Bug 1733700] Re: apparmor python tools do not understand 'include' rules

2017-12-18 Thread Jamie Strandboge
https://gitlab.com/apparmor/apparmor/merge_requests/44 -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1733700 Title: apparmor python tools do not understand 'include'

[Touch-packages] [Bug 1733700] Re: apparmor python tools do not understand 'include' rules

2017-12-18 Thread Jamie Strandboge
** Changed in: apparmor Assignee: (unassigned) => Jamie Strandboge (jdstrand) ** Changed in: apparmor Status: Triaged => In Progress -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu.

[Touch-packages] [Bug 1508146] Re: Alt+left/right arrows switch between tty consoles (Gnome Shell vanishes), cannot disable

2017-12-14 Thread Jamie Hutber
*** This bug is a duplicate of bug 1710637 *** https://bugs.launchpad.net/bugs/1710637 I moved from a AMD Radeon onto a GeForce and setting up the graphics cards, I've never seen this issue before. But now, as others have said. i get the same thing. Running 16.04 Kernal 4.4.0-97 -- You

[Touch-packages] [Bug 1737585] Re: ufw should not override procps' default of net.ipv4.tcp_syncookies=1

2017-12-11 Thread Jamie Strandboge
This was actually fixed earlier this year: http://bazaar.launchpad.net/~jdstrand/ufw/trunk/revision/972 and patched in Debian and Ubuntu via 0.35-3. I'm going to mark this as Fixed Released. Thanks for reporting this bug! :) ** Changed in: ufw (Ubuntu) Status: New => Fix Released -- You

[Touch-packages] [Bug 1733700] Re: apparmor python tools do not understand 'include' rules

2017-11-30 Thread Jamie Strandboge
@Felix Eckhofer - please see https://bugs.launchpad.net/ubuntu/+source/snapd/+bug/1734038/comments/15 -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1733700 Title:

[Touch-packages] [Bug 1733700] Re: apparmor python tools do not understand 'include' rules

2017-11-30 Thread Jamie Strandboge
. ** Also affects: apparmor Importance: Undecided Status: New ** Changed in: apparmor (Ubuntu) Assignee: Jamie Strandboge (jdstrand) => (unassigned) ** Changed in: apparmor Status: New => Triaged ** Also affects: apparmor (Ubuntu Bionic) Importance: Undecided Status:

[Touch-packages] [Bug 1734038] Re: utils don't understand «include "/where/ever"» (was: Potential regression found with apparmor test on Xenial/Zesty)

2017-11-30 Thread Jamie Strandboge
Since snapd is using this bug for its SRU blocker and we have bug #1733700 that is the same issue, I'm going to use this bug as the snapd one and for the apparmor one. ** Summary changed: - utils don't understand «include "/where/ever"» (was: Potential regression found with apparmor test on

[Touch-packages] [Bug 1733700] Re: aa-enforce fails due to syntax error in snapd.snap-confine profile

2017-11-30 Thread Jamie Strandboge
cki (zyga) => Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1733700 Title: aa-enforce fails due to syntax error in snapd.snap-confine p

<    1   2   3   4   5   6   7   8   9   10   >