Your message dated Sat, 11 Sep 2021 20:40:18 +0000
with message-id <[email protected]>
and subject line Bug#975333: fixed in msmtp 1.8.15-1
has caused the Debian Bug report #975333,
regarding msmtp: AppArmor profile breaks --file, logfile, and passwordeval
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
975333: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=975333
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: msmtp
Version: 1.8.11-2
Severity: normal

Dear Maintainer,

There are several problems in the Debian AppArmor profile that are frequently
reported to me as the upstream maintainer, but I cannot fix them since
I do not ship the AppArmor profile.

1. Option --file
   AppArmor restricts which configuration files msmtp may read. This
   breaks option --file because the user cannot chose freely anymore.

2. Option --logfile and configuration command logfile
   The AppArmor profile does not allow msmtp to write log information
   to arbitrary files, which breaks the corresponding configuration
   options and command.

3. Option --passwordeval and command passwordeval
   The AppArmor profile restricts the commands that msmtp may execute.
   This breaks the passwordeval configuration option and command.
   This restriction is documented in News.Debian, but in my opinion this
   does not make things better.

A big problem is that users do not know where to look if they get an
unexplainable "permission denied" error. Almost nobody knows that
AppArmor interferes.

A working AppArmor profile would have to allow reading, writing and
executing arbitrary files, which would make it pretty much useless.

I therefore propose to either remove the AppArmor profile or restrict it
to the msmtp-mta package, so that most users can continue using msmtp as
expected.

Best,
Martin


*** Reporter, please consider answering these questions, where appropriate ***

   * What led up to the situation?
   * What exactly did you do (or not do) that was effective (or
     ineffective)?
   * What was the outcome of this action?
   * What outcome did you expect instead?

*** End of the template - remove these template lines ***


-- System Information:
Debian Release: bullseye/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 5.9.0-2-amd64 (SMP w/32 CPU threads)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_US:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages msmtp depends on:
ii  adduser                3.118
ii  debconf [debconf-2.0]  1.5.74
ii  libc6                  2.31-4
ii  libgnutls30            3.6.15-4
ii  libgsasl7              1.8.1-4
ii  libsecret-1-0          0.20.3-1
ii  ucf                    3.0043

Versions of packages msmtp recommends:
ii  ca-certificates  20200601

Versions of packages msmtp suggests:
pn  msmtp-mta  <none>

-- debconf information excluded

--- End Message ---
--- Begin Message ---
Source: msmtp
Source-Version: 1.8.15-1
Done: Emmanuel Bouthenot <[email protected]>

We believe that the bug you reported is fixed in the latest version of
msmtp, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Emmanuel Bouthenot <[email protected]> (supplier of updated msmtp package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 11 Sep 2021 11:15:49 +0000
Source: msmtp
Architecture: source
Version: 1.8.15-1
Distribution: unstable
Urgency: medium
Maintainer: Emmanuel Bouthenot <[email protected]>
Changed-By: Emmanuel Bouthenot <[email protected]>
Closes: 942457 975333 982162 991924
Changes:
 msmtp (1.8.15-1) unstable; urgency=medium
 .
   [ Emmanuel Bouthenot ]
   * New upstream release
   * Remove patch to fix a typo in manpage
   * Bump Standards-Version to 4.6.0.1
   * Refresh lintian overrides for msmtp-mta
   * Remove patch no longer needed (cherry-picked from upstream)
   * Remove useless HomePage field in upstream/metadata
   * Bump Standards-Version to 4.6.0.1
   * Update AppArmor profile to support gssapi authentication. Thanks to
     Stewart Smith for the feedback (Closes: #991924).
   * Make possible to disable AppArmor profile through a debconf question
     (disabled by default) (Closes: #942457, #975333, #982162).
 .
   [John Scott]
   * Add upstream release signing key and do validation in debian/watch.
 .
   [ Simon Deziel ]
   * Apparmor: allow access to Gnome keyring via DBus
Checksums-Sha1:
 6f2b16d1f21f3b01b22fad6c4547c7ba7afef776 2200 msmtp_1.8.15-1.dsc
 1208db3da0db71c0615b11bf91a072f2297e10f6 370736 msmtp_1.8.15.orig.tar.xz
 e5f89e717a50b42eca5d9c90dc86d5a3d27ad71b 488 msmtp_1.8.15.orig.tar.xz.asc
 85ea79635c843f9cf67d40414fe889c4ccf989db 19712 msmtp_1.8.15-1.debian.tar.xz
 13b66efd5b9c38203252e648f073e20cecc792ad 8192 msmtp_1.8.15-1_source.buildinfo
Checksums-Sha256:
 07e45d822b63eeb885b80ed62f9b0cced5c44c402b5fc8c7e04c043e59dc2b9f 2200 
msmtp_1.8.15-1.dsc
 2265dc639ebf2edf3069fffe0a3bd76749f8b58f4001d5cdeae19873949099ce 370736 
msmtp_1.8.15.orig.tar.xz
 1eb40930792f76319cbb4cc665c4db017d2c5346ba3a44112787b020533ad269 488 
msmtp_1.8.15.orig.tar.xz.asc
 dbfe55d42a6b9c897f39a17fdcac0423f99ea5dcc940bc4405dac625764551b6 19712 
msmtp_1.8.15-1.debian.tar.xz
 66fd4e4b29e9187fe5772384a75017ec173782418c641a76fe1d7d95d5bbc763 8192 
msmtp_1.8.15-1_source.buildinfo
Files:
 20cc1aef8f10d9e2118f82048f6fbf8c 2200 mail optional msmtp_1.8.15-1.dsc
 45eddbc0e93d7eb77c12ab75b5e1e6be 370736 mail optional msmtp_1.8.15.orig.tar.xz
 49118dea09bb3b820fbc3527db4c5a10 488 mail optional msmtp_1.8.15.orig.tar.xz.asc
 2b0367b0358c8ebba406ee9b70a65d4e 19712 mail optional 
msmtp_1.8.15-1.debian.tar.xz
 8bf5fae6deccffa08618aa086d4fa523 8192 mail optional 
msmtp_1.8.15-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEETQ1Tfow3vJnf8QuHSwd3I5KdQsMFAmE9DDMACgkQSwd3I5Kd
QsNzmhAAgS7vFY/CtHk8i7Wca8jWRfyhRTfjt5ZTj/I0/BGWlnXZdd5DjscTgSgV
6VRXCVr+bXQDMZmITEEdeTUg+bRVm+e2+8mc0rTgXH60P+gp2mEwBl7upkatzaQy
bfIAIURqFhGzjr430GvhBqFQORwEsW9Y+n19TGZMZv+YoVSPp4lRoQASA+PfSLbO
RNMh/19L1x82hGMzeARIrL9I1YqhqbQWeJJmLXaupMoPw+TudPhxUH7B+eAFmv/2
+UVtIvLu/lhEzPETI7iBIiTWAix1EK13xeE1goiQENM96Osm4JiXUFV38yv54BsF
IkrvXhGuFiGgGF5KCjPnIvweBMV+RuvnS5ilGPAygFXAQiilgdyOM7z8ybQ0HIum
lKYFmy8WeycZ6IhpVjhnglhH3H0VLL13upg558GO0qfQknyRUNKbwwOTiwR7/mVp
sbKyaBzPeLQ3cVumg5juwxV8eoxs3bbcrK5huPpz1J1OJ+DKNk3PgqGayjps6gZe
yTkfj9tsyUAFKtn9Lf61CD9vy3NEaOdygJHjuZ2ibCD+aQXoPnzKR3gFQs8VWaKk
ebytNLpGgrTr9IaJScMTZ/yuZ0vcjNMV8QWF8ui35hXM3Yq4vt+zK8EK/JxjHnt2
o+hZorX4Bl5h7jHZbD+1eYMQ+EDarAmoZ6arqBPYZ2+TKCkcHmQ=
=ZebL
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to