[Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2017-01-18 Thread Launchpad Bug Tracker
This bug was fixed in the package apparmor - 2.10.95-0ubuntu2.5~14.04.1 --- apparmor (2.10.95-0ubuntu2.5~14.04.1) trusty; urgency=medium * Bring apparmor 2.10.95-0ubuntu2.5, from Ubuntu 16.04, to Ubuntu 14.04. - This allows for proper snap confinement on Ubuntu 14.04 when using

[Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2017-01-18 Thread Launchpad Bug Tracker
This bug was fixed in the package dbus - 1.6.18-0ubuntu4.5 --- dbus (1.6.18-0ubuntu4.5) trusty; urgency=medium * debian/patches/unrequested-reply-mediation.patch: Don't let unrequested reply messages through and don't audit them. Unrequested reply messages are error or

[Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2016-12-22 Thread Tyler Hicks
I've completed my verification of the dbus 1.6.18-0ubuntu4.5 SRU. The documented Test Plan went as expected. It leverages extensive automated tests that were written when the AppArmor D-Bus mediation patch set was upstreamed into the D-Bus project. I am confident of the dbus SRU and feel like it

[Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2016-12-22 Thread Tyler Hicks
I've completed my verification of the apparmor 2.10.95-0ubuntu2.5~14.04.1 SRU. Testing very went well and I did not uncover any issues. I completed the entire Test Case as documented in the bug description. The AppArmor test plan was completed on the 14.04 release and HWE kernels as well as all of

[Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2016-12-14 Thread Tyler Hicks
** Description changed: = apparmor SRU = [Rationale] For backporting snapd to 14.04 LTS, we need to provide proper AppArmor confinement for snaps when running under the 16.04 hardware enablement kernel. The apparmor userspace package in 14.04 is missing support key mediation features

[Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2016-12-14 Thread Tyler Hicks
** Description changed: = apparmor SRU = [Rationale] For backporting snapd to 14.04 LTS, we need to provide proper AppArmor confinement for snaps when running under the 16.04 hardware enablement kernel. The apparmor userspace package in 14.04 is missing support key mediation features

[Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2016-12-09 Thread Timo Aaltonen
Hello Tyler, or anyone else affected, Accepted apparmor into trusty-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.5~14.04.1 in a few hours, and then in the -proposed repository. Please help us by testing this new package.

[Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2016-12-07 Thread Brian Murray
Hello Tyler, or anyone else affected, Accepted dbus into trusty-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.5 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See

[Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2016-12-01 Thread Tyler Hicks
The old apparmor upload has been rejected and I'll be uploading a new version shortly. ** Changed in: apparmor (Ubuntu Trusty) Status: Incomplete => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2016-11-30 Thread Tyler Hicks
** Description changed: = apparmor SRU = [Rationale] For backporting snapd to 14.04 LTS, we need to provide proper AppArmor confinement for snaps when running under the 16.04 hardware enablement kernel. The apparmor userspace package in 14.04 is missing support key mediation features

[Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2016-11-30 Thread Tyler Hicks
Moving the apparmor task back to "incomplete" while I gather info for https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1628285/comments/10. ** Description changed: + = apparmor SRU = [Rationale] For backporting snapd to 14.04 LTS, we need to provide proper AppArmor confinement for

Re: [Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2016-11-29 Thread Tyler Hicks
On 11/12/2016 12:24 PM, Steve Langasek wrote: > Tyler, are there any packages shipping apparmor profiles in 14.04 that > have /not/ been covered by this test plan? There are some that are not covered. Using the output of `reverse-depends -br trusty dh-apparmor`, the remainders are: akonadi

[Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2016-11-29 Thread Tyler Hicks
** Description changed: [Rationale] For backporting snapd to 14.04 LTS, we need to provide proper AppArmor confinement for snaps when running under the 16.04 hardware enablement kernel. The apparmor userspace package in 14.04 is missing support key mediation features such as UNIX domain

[Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2016-11-29 Thread Tyler Hicks
** Description changed: [Rationale] For backporting snapd to 14.04 LTS, we need to provide proper AppArmor confinement for snaps when running under the 16.04 hardware enablement kernel. The apparmor userspace package in 14.04 is missing support key mediation features such as UNIX domain

[Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2016-11-29 Thread Tyler Hicks
** Description changed: [Rationale] For backporting snapd to 14.04 LTS, we need to provide proper AppArmor confinement for snaps when running under the 16.04 hardware enablement kernel. The apparmor userspace package in 14.04 is missing support key mediation features such as UNIX domain

[Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2016-11-29 Thread Tyler Hicks
** Description changed: [Rationale] For backporting snapd to 14.04 LTS, we need to provide proper AppArmor confinement for snaps when running under the 16.04 hardware enablement kernel. The apparmor userspace package in 14.04 is missing support key mediation features such as UNIX domain

[Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2016-11-12 Thread Steve Langasek
Tyler, are there any packages shipping apparmor profiles in 14.04 that have /not/ been covered by this test plan? Does the dbus task imply that there need to be any versioned Breaks/Depends between these two SRUs, or are the two packages bidirectionally compatible? (i.e. dbus is needed because

[Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2016-11-11 Thread Tyler Hicks
Adding a dbus task because its AppArmor mediation patches need to be updated to provide unrequested reply protection to prevent two D-Bus connections from bypassing security policies by communicating via reply and/or error D-Bus messages. ** Also affects: dbus (Ubuntu) Importance: Undecided

[Bug 1641243] Re: Provide full AppArmor confinement for snaps on 14.04

2016-11-11 Thread Tyler Hicks
** Description changed: [Rationale] For backporting snapd to 14.04 LTS, we need to provide proper AppArmor confinement for snaps when running under the 16.04 hardware enablement kernel. The apparmor userspace package in 14.04 is missing support key mediation features such as UNIX domain