Re: [apparmor] [patch] Add network 'smc' keyword in NetworkRule and apparmor.d manpage

2017-08-29 Thread Seth Arnold
On Tue, Aug 29, 2017 at 10:55:07PM +0200, Christian Boltz wrote: > Hello, > > 'smc' seems to be new in kernel 4.12. > > > I propose this patch for trunk, 2.11 and 2.10. Acked-by: Seth Arnold Thanks > Note that the 2.10 apparmor.d manpage also misses the 'kcm' keyword, so > I'll also add it t

[apparmor] [patch] Add network 'smc' keyword in NetworkRule and apparmor.d manpage

2017-08-29 Thread Christian Boltz
Hello, 'smc' seems to be new in kernel 4.12. I propose this patch for trunk, 2.11 and 2.10. Note that the 2.10 apparmor.d manpage also misses the 'kcm' keyword, so I'll also add it there. 2.9 doesn't have NetworkRule, and it's unlikely that someone expects the manpage on that old branch to mat

Re: [apparmor] [PATCH] RFC: Add Apparmor policy matching to IMA

2017-08-29 Thread Matthew Garrett
On Tue, Aug 29, 2017 at 12:47 PM, John Johansen wrote: > On 08/29/2017 12:04 PM, Matthew Garrett wrote: >> IMA has support for matching based on security context, but this is >> currently limited to modules that implement the audit_rule_match hook. >> The infrastructure around this seems to depend

Re: [apparmor] [PATCH] RFC: Add Apparmor policy matching to IMA

2017-08-29 Thread John Johansen
On 08/29/2017 12:04 PM, Matthew Garrett wrote: > IMA has support for matching based on security context, but this is > currently limited to modules that implement the audit_rule_match hook. > The infrastructure around this seems to depend on having 32 bit security > IDs to reference the policy asso

Re: [apparmor] [patch] Samba profile updates for ActiveDirectory / Kerberos

2017-08-29 Thread Christian Boltz
Hello, Am Dienstag, 29. August 2017, 03:38:53 CEST schrieb Seth Arnold: > On Tue, Aug 22, 2017 at 11:14:59PM +0200, Christian Boltz wrote: > > > Is the sss/ms/initgroups change intentional? > > > > Yes, this is intentional - I did the profile updates (on an INVIS > > server) myself ;-) > > > > >