Trying to revive some old bugs that seem forgotten for too long.
I think the discussion came to a point where:
1. The apparmor rule that would need to be added is clear
2. Adding it by default is considered not safe
3. The fix therefore can only be to ensure users that want to use it this way
Well this bug now affects at least two persons as I am also encountering
it on ubuntu 20.04.
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1842695
Title:
ClamAV AppArmor profiles do not allow
Let me slightly revise what legovini wrote (and appologies to legovini
who was just passing on my less than adequate explanation).
It is true that giving cap sys_admin is effectively giving a process
root. That doesn't mean we don't do it, but we do it very carefully, and
only after review of the