Hi,

tl;dr: please test the packages you maintain, that ship AppArmor
policy, on tesitng/sid with apparmor 5.0.x from experimental.

You're receiving this email because you are in the Maintainer field
for at least 1 package that ships files in /etc/apparmor.d/.

Forky will ship with the AppArmor 5.0.x userspace. Together with
Forky's kernel, this enables finer grained confinement rules than what
we had in Trixie.

The main changes are:

 - Fine-grained D-Bus confinement: in Trixie, any D-Bus rule would be
   silently upgraded to "allow any D-Bus operation" (which in many
   cases is a sandbox escape); while in Forky, fine-grained rules will
   be honored, and any D-Bus operation that's not explicitly allowed
   will be denied.

 - Unix socket rules and network rules: I'm not sure about the details
   but I understand the situation is similar to D-Bus.

So there's a chance the policy you ship in your packages will become
more restrictive on Forky, which may break functionality.

To make the transition smoother, please test the packages you maintain
that ship AppArmor policy, on a testing/sid system, with apparmor
5.0.x from experimental, and ensure the policy you ship is compatible.

Usually you can upload to sid any required policy update: most of the
changes you'll have to do will be no-op's there until the apparmor
5.0.x userspace is in sid. And uploading the fixes early makes life
easier for other folks who are using the apparmor 5.0.x userspace
from experimental.

I intend to upload apparmor 5.0.x to sid no earlier than October 26.

Thank you!
-- 
intrigeri

Reply via email to