[Bug 690040] Re: no longer confined by AppArmor

2011-01-06 Thread Launchpad Bug Tracker
This bug was fixed in the package cups - 1.4.4-6ubuntu2.3 --- cups (1.4.4-6ubuntu2.3) maverick-security; urgency=low * ubuntu-upstart.dpatch: update to explicitly load the AppArmor profile to avoid race condition where cups could load before AppArmor and run unconfined (LP:

[Bug 690040] Re: no longer confined by AppArmor

2011-01-06 Thread Jamie Strandboge
** Tags added: apparmor -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/690040 Title: no longer confined by AppArmor -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com

[Bug 690040] Re: no longer confined by AppArmor

2011-01-04 Thread Launchpad Bug Tracker
** Branch linked: lp:~pitti/cups/debian-trunk -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/690040 Title: no longer confined by AppArmor -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com

[Bug 690040] Re: no longer confined by AppArmor

2011-01-04 Thread Jamie Strandboge
** Changed in: cups (Ubuntu Maverick) Assignee: Martin Pitt (pitti) = Jamie Strandboge (jdstrand) ** Changed in: cups (Ubuntu Maverick) Status: Triaged = In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 690040] Re: no longer confined by AppArmor

2011-01-04 Thread Jamie Strandboge
** Changed in: cups (Ubuntu Maverick) Importance: Undecided = High ** Changed in: cups (Ubuntu Natty) Importance: Undecided = High -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/690040 Title:

[Bug 690040] Re: no longer confined by AppArmor

2011-01-04 Thread Jamie Strandboge
I have uploaded an updated package using the attached debdiff to the security PPA. ** Changed in: cups (Ubuntu Maverick) Status: In Progress = Fix Committed ** Patch added: cups_1.4.4-6ubuntu2.3.debdiff

[Bug 690040] Re: no longer confined by AppArmor

2011-01-04 Thread Launchpad Bug Tracker
** Branch linked: lp:debian/sid/cups -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/690040 Title: no longer confined by AppArmor -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com

[Bug 690040] Re: no longer confined by AppArmor

2011-01-03 Thread Launchpad Bug Tracker
This bug was fixed in the package cups - 1.4.5-1ubuntu5 --- cups (1.4.5-1ubuntu5) natty; urgency=low * Use AppArmor profile loading helper (LP: #690040): - debian/patches/ubuntu-upstart.dpatch: load profile. - debian/control: Depend on upstart. -- Kees Cook k...@ubuntu.com

[Bug 690040] Re: no longer confined by AppArmor

2011-01-03 Thread Launchpad Bug Tracker
** Branch linked: lp:ubuntu/cups -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/690040 Title: no longer confined by AppArmor -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com

[Bug 690040] Re: no longer confined by AppArmor

2010-12-20 Thread Kees Cook
Helper script for upstart is now bug 692801. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/690040 Title: no longer confined by AppArmor -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com

[Bug 690040] Re: no longer confined by AppArmor

2010-12-17 Thread Jamie Strandboge
** Changed in: cups (Ubuntu Natty) Milestone: None = natty-alpha-2 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/690040 Title: no longer confined by AppArmor -- ubuntu-bugs mailing list

[Bug 690040] Re: no longer confined by AppArmor

2010-12-14 Thread Martin Pitt
Kees, thanks for pointing out. I guess for maverick we won't get around adding these extra calls to the upstart script, but this is really expensive (it starts a big perl process for each of those). For natty, is it planned to move apparmor to an upstart job, so that jobs can just wait for it to

[Bug 690040] Re: no longer confined by AppArmor

2010-12-14 Thread Kees Cook
Perl? What? No, it should just use the logic all the other services do. For example: pre-start script [ -d /sys/module/apparmor ] || exit 0 [ -x /sbin/apparmor_parser ] || exit 0 /sbin/apparmor_parser -r -W /etc/apparmor.d/usr.sbin.avahi-daemon || true end script There will be a

[Bug 690040] Re: no longer confined by AppArmor

2010-12-14 Thread Kees Cook
Sorry, it should also include a test for being enabled (this is missing from avahi, but is what others are using aa-status for). read profile /sys/kernel/security/apparmor/profiles || true [ -z $profile ] exit 0 # quit if disabled -- You received this bug notification because you are a member

[Bug 690040] Re: no longer confined by AppArmor

2010-12-14 Thread Kees Cook
(Or not, since this is early-boot and there may be no profiles loaded yet, so we should skip that test.) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/690040 Title: no longer confined by AppArmor

[Bug 690040] Re: no longer confined by AppArmor

2010-12-13 Thread Kees Cook
** Also affects: cups (Ubuntu Maverick) Importance: Undecided Status: New ** Also affects: cups (Ubuntu Natty) Importance: Undecided Status: New ** This bug has been flagged as a security vulnerability -- You received this bug notification because you are a member of

[Bug 690040] Re: no longer confined by AppArmor

2010-12-13 Thread Kees Cook
This is a race between /etc/init/cups and /etc/init.d/apparmor. /etc/init/cups should include a stanza to load the AppArmor profile like all the other /etc/init services that have AppArmor profiles. $ sudo aa-status ... 1 processes are unconfined but have a profile defined. /usr/sbin/cupsd

[Bug 690040] Re: no longer confined by AppArmor

2010-12-13 Thread Kees Cook
Workaround: sudo service cups restart -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/690040 Title: no longer confined by AppArmor -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com

[Bug 690040] Re: no longer confined by AppArmor

2010-12-13 Thread Till Kamppeter
** Changed in: cups (Ubuntu Maverick) Assignee: (unassigned) = Martin Pitt (pitti) ** Changed in: cups (Ubuntu Natty) Assignee: (unassigned) = Martin Pitt (pitti) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.