AFAICS e83fa67edfb534976dc4133e634519084153c0e7 got backported before
2.13.2 (8661ebcb7910e03bfcdb6fbf99616120a398d576). And the
apparmor_parser binary has the --compile-features flag in the version in
buster.

I tested with both the versions from buster (2.13.2-10) and sid (2.13.3-4):
apparmor_parser --kernel-features /usr/share/apparmor-features/features 
--features-file /usr/share/apparmor-features/features -a usr.sbin.unbound

after removing the policy beforehand.

(and various other combinations of --features-file, --compile-features,
--kernel-features)

The result with all cases is that apparmor prevents unbound from
creating sockets and thus starting.

I hope the test was correct.

Thanks!

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1842459

Title:
  apparmor abi-feature pinning not working with Disco and Eoan kernels

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1842459/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to