Re: [apparmor] [patch] /usr/lib/dovecot/auth and mysql

2014-02-02 Thread John Johansen
On 01/26/2014 03:17 PM, Christian Boltz wrote: Hello, this patch is an interesting one - /usr/lib/dovecot/auth reads the mysql config files, which is not covered by abstractions/mysql. Now the interesting question is where we should add this. a) add it to abstractions/mysql because it

Re: [apparmor] [patch] usr.bin.dovecot profile

2014-02-02 Thread John Johansen
On 01/26/2014 03:35 PM, Christian Boltz wrote: Hello, after testing the dovecot profiles on a new server, I noticed /usr/sbin/dovecot needs some more permissions: -mysql access - execution permissions for /usr/lib/dovecot/dict and lmtp - write access to some postfix sockets, used to -

Re: [apparmor] [patch] dovecot profiles - use abstractions/nameservice

2014-02-02 Thread John Johansen
On 01/26/2014 03:07 PM, Christian Boltz wrote: Hello, after testing the dovecot profiles on a new server, I noticed /usr/lib/dovecot/dict and /usrlib/dovecot/lmtp need more nameservice- related permissions. Therefore I propose to include abstractions/nameservice instead of adding more

Re: [apparmor] [patch] logprof.conf and UsrMove

2014-02-02 Thread John Johansen
On 01/28/2014 12:20 PM, Christian Boltz wrote: Hello, logprof.conf contains a list of binaries in the [qualifiers] section that should for example never have their own profile. Since some distributions moved lots of files from /bin/ to /usr/bin/ (UsrMove), this list is outdated. The

Re: [apparmor] systemd AppArmorProfile=

2014-02-02 Thread Christian Boltz
Hello, Am Sonntag, 2. Februar 2014 schrieb Michael Scherer: Le samedi 01 février 2014 à 18:18 +0100, Christian Boltz a écrit : BTW: It looks like your patch requires the profiles to be loaded already. Do you have any plans for loading, reloading or removing profiles via systemd? I had