Bug#735470: [apparmor] Fwd: Bug#735470: Could be implemented centrally with a dpkg trigger instead of requiring every package shipping an apparmor file to use dh_apparmor

2014-01-17 Thread Didier 'OdyX' Raboud
Le jeudi, 16 janvier 2014, 14.49:06 Kees Cook a écrit : On Thu, Jan 16, 2014 at 07:37:04PM +0100, Didier 'OdyX' Raboud wrote: man deb-trigggers contradicts you, in my reading; an 'activate /etc/apparmor.d' triggers' file in apparmor would make its action run _before_ cups (which would have

Bug#735470: [apparmor] Fwd: Bug#735470: Could be implemented centrally with a dpkg trigger instead of requiring every package shipping an apparmor file to use dh_apparmor

2014-01-16 Thread Didier 'OdyX' Raboud
Hi Seth, Le mercredi, 15 janvier 2014, 11.14:07 Seth Arnold a écrit : On Wed, Jan 15, 2014 at 07:30:52PM +0100, intrigeri wrote: From: Didier Raboud o...@debian.org apparmor could have an 'interest /etc/apparmor.d/' triggers file and its postinst would then do the machinery to create (or

Bug#735470: [apparmor] Fwd: Bug#735470: Could be implemented centrally with a dpkg trigger instead of requiring every package shipping an apparmor file to use dh_apparmor

2014-01-16 Thread Kees Cook
On Thu, Jan 16, 2014 at 11:11:22AM +0100, Didier 'OdyX' Raboud wrote: Le mercredi, 15 janvier 2014, 11.14:07 Seth Arnold a écrit : On Wed, Jan 15, 2014 at 07:30:52PM +0100, intrigeri wrote: From: Didier Raboud o...@debian.org apparmor could have an 'interest /etc/apparmor.d/' triggers

Bug#735470: [apparmor] Fwd: Bug#735470: Could be implemented centrally with a dpkg trigger instead of requiring every package shipping an apparmor file to use dh_apparmor

2014-01-16 Thread Didier 'OdyX' Raboud
Le jeudi, 16 janvier 2014 10.14:14, vous avez écrit : On Thu, Jan 16, 2014 at 11:11:22AM +0100, Didier 'OdyX' Raboud wrote: As far as I understand deb-triggers' manpage, this can be enforced using 'activate /etc/apparmor.d/', which will then make the trigger run at the start of the

Bug#735470: [apparmor] Fwd: Bug#735470: Could be implemented centrally with a dpkg trigger instead of requiring every package shipping an apparmor file to use dh_apparmor

2014-01-16 Thread Kees Cook
On Thu, Jan 16, 2014 at 07:37:04PM +0100, Didier 'OdyX' Raboud wrote: Le jeudi, 16 janvier 2014 10.14:14, vous avez écrit : On Thu, Jan 16, 2014 at 11:11:22AM +0100, Didier 'OdyX' Raboud wrote: As far as I understand deb-triggers' manpage, this can be enforced using 'activate

Bug#735470: [apparmor] Fwd: Bug#735470: Could be implemented centrally with a dpkg trigger instead of requiring every package shipping an apparmor file to use dh_apparmor

2014-01-15 Thread Seth Arnold
On Wed, Jan 15, 2014 at 07:30:52PM +0100, intrigeri wrote: Didier Raboud suggested to use dpkg triggers for what dh_apparmor does, and is happy to give a hand. See the attached message. Thank you, Didier! What do the original dh_apparmor authors / Ubuntu folks think? Any reason Didier