This bug was fixed in the package click-apparmor - 0.1.10
---------------
click-apparmor (0.1.10) saucy; urgency=low
* work around lack of first boot postinst-style code in lxc-android-config
and ship a click-apparmor upstart job. This checks to see if apparmor or
apparmor-easyprof-ubuntu's dpkg md5sums changed, and if so, runs
'aa-clickhook -f'. This allows us to update policy for click packages on
reboot after system-image updates. Note, the click system hooks job is
not enough, because that correctly uses 'aa-clickhook' without arguments.
'aa-clickhook -f' isn't normally needed so this job completes quickly
in typical reboots ('aa-clickhook -f' still only updates the click policy
that is affected). (LP: #1229449)
* don't verify the policy before load. It will error on load which is
equivalent to erroring out before load. This allows us to avoid parsing
policy twice which can save significant time when regenerating lots of
profiles, which is important during first boot after system upgrade
* generated policy should be readable by everyone (the click security
manifests are not private)
* fix default path to apparmor_parser (thus avoiding a needless 'which')
* debian/rules: cleanup .coverage and apparmor/__pycache__
-- Jamie Strandboge <[email protected]> Mon, 23 Sep 2013 14:11:03 -0500
** Changed in: click-apparmor (Ubuntu Saucy)
Status: In Progress => Fix Released
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1229449
Title:
[FFe] need method to reload policy on first boot after system-image
upgrade
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/click-apparmor/+bug/1229449/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs