[apparmor] apparmor IRC monthly meeting today (June 11)

2013-06-11 Thread John Johansen
We will be holding our monthly IRC meeting in #apparmor on oftc.net at 20:00 UTC sorry for the late notice, I have my calendar setup to send out an email, but not only did it not send out the email, it didn't send me the notification it was supposed to either. -- AppArmor mailing list

Re: [apparmor] DBus rule syntax for subject and peer components

2013-06-11 Thread John Johansen
On 06/10/2013 06:44 PM, Tyler Hicks wrote: I've profiled the system and session bus activity of gnome-screensaver to provide examples of various DBus policy ideas generated in a previous apparmor list thread[1]. To start us off, here's the profile using the current DBus syntax. It is

Re: [apparmor] DBus rule syntax for subject and peer components

2013-06-11 Thread Jamie Strandboge
On 06/10/2013 08:44 PM, Tyler Hicks wrote: There are a few changes needed for the new syntax: 1. dest= will be changed to name= so that it can identify either the subject's or the peer's connection name without causing confusion 2. method= will be changed to member= so that it can

Re: [apparmor] DBus rule syntax for subject and peer components

2013-06-11 Thread Tyler Hicks
This was a good exercise because none of the proposals were mine and I had to try to understand other people's proposals and think a bit like them. On 2013-06-10 18:44:13, Tyler Hicks wrote: * Proposal 1 - Leveraging the meaning of arrows Based on Seth's suggestion[2]. It eliminates the send

Re: [apparmor] DBus rule syntax for subject and peer components

2013-06-11 Thread Jamie Strandboge
On 06/11/2013 04:41 PM, Tyler Hicks wrote: ... As a side note, one thing that I'm not real happy about is the asymmetry of send and receive rules. When writing a send rule, it doesn't make sense to have a path, interface, or member specified in the subject address grouping. When writing

Re: [apparmor] [patch] fix libapparmor ruby bindings for ruby 2.0

2013-06-11 Thread Steve Beattie
On Wed, Jun 05, 2013 at 10:23:41PM +0200, Christian Boltz wrote: you might have noticed the discussion about the libapparmor ruby bindings build failures on openSUSE Factory, which is the first version with ruby 2.0. The problem was that DESTDIR was added to too many variables, which

Re: [apparmor] DBus rule syntax for subject and peer components

2013-06-11 Thread Seth Arnold
On Mon, Jun 10, 2013 at 06:44:13PM -0700, Tyler Hicks wrote: To start us off, here's the profile using the current DBus syntax. It is complex, but it uses all of the DBus accesses (send, receive, and acquire) and it is representative of what a real profile may look like. Thanks for this. These