[apparmor] What replaced aa-status command if no compability patch applied to kernel ?

2012-06-15 Thread Aaron Lewis
mmand ? I failed to find a compability patch of linux 3.4 , since it changed a lot after linux 3.3 , i'm not able to fix the patch(for 3.3) myself .. Environment: linux kernel 3.4 + Apparmor 2.8 userspace toolset , latest arch linux Thanks ! -- B

[apparmor] Need help on fixing firefox apparmor rule

2012-11-24 Thread Aaron Lewis
quot;name" looked way too wired to me, should I just add a "XXX r," ? Or it's something specific to .. dbus or systemd? -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://keyserver.veridis.com ) Finger Print: 9482 448F C7C3 896C 1DFE 7DD3 2492 A7D0 DFE6 C29E -- AppA

[apparmor] Compatibility patch for 3.6 kernel

2012-12-15 Thread Aaron Lewis
Hi, I couldn't use aa-genprof on 3.6 kernel, since I couldn't find the compatibility patch. Anyone know how to work out that issue? -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://keyserver.veridis.com ) Finger Print: 9482 448F C7C3 896C 1DFE 7DD3 2492 A7D0 DFE6 C29E --

[apparmor] "_" in profile name

2012-12-16 Thread Aaron Lewis
Hi, Looks like a bug of apparmor, Application.Binaries.skype_static-2.2.0.25.skype If I change the path from skype_static-2.2.0.25 to skype, "Application.Binaries.skype.skype" works. Was it a bug? Or do I get a list of bad chars? -- Best Regards, Aaron Lewis - PGP: 0xDFE6C

[apparmor] aa-genprof no longer works on my system

2012-12-31 Thread Aaron Lewis
rent=5390 profile="/usr/lib/virtualbox/VBoxSVC//null-2d" name="/sys/class/power_supply/" pid=5457 comm=4143504920506F6C6C6572 requested_mask="r" denied_mask="r" fsuid=1000 ouid=0 -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://keyserver.veridis.c

[apparmor] I believe I found another problem

2013-01-01 Thread Aaron Lewis
quot; requested_mask="r400 audit(1357051673.142:13897): apparmor="ALLOWED" operation="open" parent=1 profile="/usr/lib/virtualbox/VBoxHeadless//null-31" name="/dev/disk/by-path/" pid=7556 comm="VBoxSVC" requested_mask="r" denied_mask

[apparmor] Need help on defining rules for these two denied "open" operations

2013-01-07 Thread Aaron Lewis
name="/dev/shm/" pid=10275 comm="ShFolders" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0 And When it's finished, how am I supposed to upload the profile? I mean for the community -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://keyserv

[apparmor] Was it necessary to use both "/Extra/ rw" and "/Extra/** rw"

2013-01-07 Thread Aaron Lewis
Hi, If I granted a program to with /Extra/** rw Do I still need: /Extra rw Thanks! -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://keyserver.veridis.com ) Finger Print: 9482 448F C7C3 896C 1DFE 7DD3 2492 A7D0 DFE6 C29E -- AppArmor mailing list AppArmor@lists.ubuntu.com Modify

[apparmor] Fwd: [Patch] Fix date time log parsing for 2.8.1

2013-01-08 Thread Aaron Lewis
-- Forwarded message -- From: Aaron Lewis Date: Tue, Jan 8, 2013 at 9:01 PM Subject: Re: [apparmor] [Patch] Fix date time log parsing for 2.8.1 To: John Johansen Cool, just tested on Arch Linux, apparmor-2.8.0 from AUR Works! I'll give more tests tomorrow, thanks John! O

[apparmor] Syntax error for folder creating?

2013-01-08 Thread Aaron Lewis
Hi, I don't know why, while creating profile for chromium, /usr/lib/chromium/extensions/ c, aa-parser just complains -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://pgp.mit.edu/ ) Finger Print: 9482 448F C7C3 896C 1DFE 7DD3 2492 A7D0 DFE6 C29E -- AppArmor mailing list App

[apparmor] [profile] for usr.lib.chromium.chromium

2013-01-08 Thread Aaron Lewis
Here I attached profile for usr.lib.chromium.chromium Plus mozilla plugin support, gtalk plugin support (adjust your installation path if not /opt/google/talkplugin/) -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://pgp.mit.edu/ ) Finger Print: 9482 448F C7C3 896C 1DFE 7DD3 2492 A7D0

[apparmor] Bluetooth raw socket?

2013-01-08 Thread Aaron Lewis
shark" pid=17677 comm="dumpcap" family="bluetooth" sock_type="raw" protocol=1 Wireshark doesn't run dumpcap .. Thanks! -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://pgp.mit.edu/ ) Finger Print: 9482 448F C7C3 896C 1DFE 7DD3 2492 A7D0 DFE6 C29E

[apparmor] [SOLVED] Re: Bluetooth raw socket?

2013-01-08 Thread Aaron Lewis
Thanks, that worked On Wed, Jan 9, 2013 at 9:21 AM, John Johansen wrote: > On 01/08/2013 04:58 PM, Aaron Lewis wrote: >> Hi, >> >> Looks like raw socket itself doesn't include bluetooth socket, >> >> capability net_raw, >> network pack

[apparmor] [SOLVED] Re: [profile] for usr.lib.chromium.chromium

2013-01-08 Thread Aaron Lewis
apparmor-profiles in Ubuntu). > > [1]https://lists.ubuntu.com/archives/apparmor/2011-January/000767.html > > -- > Jamie Strandboge http://www.ubuntu.com/ > > -- > AppArmor mailing list > AppArmor@lists.ubuntu.com > Modify settings or unsubscribe at: > https:/

Re: [apparmor] [SOLVED] Re: [profile] for usr.lib.chromium.chromium

2013-01-09 Thread Aaron Lewis
e: > Hello, > > Am Mittwoch, 9. Januar 2013 schrieb Aaron Lewis: >> I made few tweaks (xfce4, /proc /sys etc.) and the profile / patch is >> attached here. > > Looks like you forgot the attachment - can you please try again? ;-) > > > Regards, > &

Re: [apparmor] [profile] for usr.lib.chromium.chromium

2013-01-11 Thread Aaron Lewis
Patch is here, serveral tweaks, (To work on Arch a subsitute is required: s#/chromium/#/chromium-browser/#) - --- usr.bin.chromium-browser2013-01-11 20:49:18.040009935 +0800 +++ usr.bin.chromium2013-01-11 21:21:01.923418185 +0800 @@ -8,6 +8,7 @@ #include #include #include

[apparmor] Reading locally stored html files

2013-01-11 Thread Aaron Lewis
Hi, Was it safe to allow chromium to read locally stored html files, with: /{**,}/*.{css,xml,gif,png,jpg,jpeg,html,htm} r, Or what you suggest on things like this? (The one Jamie created doesn't include such thing yet) -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://pgp.mi

[apparmor] [Profile] virtualbox headless plus vboxnetadpctl

2013-01-11 Thread Aaron Lewis
Hi, Here's the profile I wrote for VBoxHeadless and the required component VboxNetAdpCtl. That was created on Arch, *there* might be a minor difference on Ub. -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://pgp.mit.edu/ ) Finger Print: 9482 448F C7C3 896C 1DFE 7DD3 2492 A7D0 DFE6

[apparmor] [Profile] Kchmviewer, and changes on

2013-01-11 Thread Aaron Lewis
rrc r, owner @{HOME}/.config/Ulduzsoft/* rwk, owner @{HOME}/.kchmviewer/{**,} rw, } -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://pgp.mit.edu/ ) Finger Print: 9482 448F C7C3 896C 1DFE 7DD3 2492 A7D0 DFE6 C29E -- AppArmor mailing list AppArmor@lists.ubuntu.com Modify settings or unsubscri

Re: [apparmor] Reading locally stored html files

2013-01-11 Thread Aaron Lewis
Right, I should limit the file locations instead, Thanks! On 10:24 Fri 11 Jan , Jamie Strandboge wrote: > On 01/11/2013 07:28 AM, Aaron Lewis wrote: > > Hi, > > > > Was it safe to allow chromium to read locally stored html files, > > with: > > > >

[apparmor] [profile] usr.bin.weechat-curses

2013-01-11 Thread Aaron Lewis
Hi, Below is the profile for weechar-curses -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://pgp.mit.edu/ ) Finger Print: 9482 448F C7C3 896C 1DFE 7DD3 2492 A7D0 DFE6 C29E # Last Modified: Sat Jan 12 15:43:56 2013 #include /usr/bin/weechat-curses { #include #include #include

[apparmor] Allowing read access to anonymous huge pages

2013-01-21 Thread Aaron Lewis
ot; denied_mask="r" fsuid=1000 ouid=1000 Adding that /anon stuff doesn't help, logs still available. Any ideas? Thanks! -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://pgp.mit.edu/ ) Finger Print: 9482 448F C7C3 896C 1DFE 7DD3 2492 A7D0 DFE6 C29E -- AppArmor

Re: [apparmor] [Profile] Kchmviewer, and changes on

2013-01-22 Thread Aaron Lewis
On 05:46 Tue 22 Jan , John Johansen wrote: > On 01/11/2013 07:29 PM, Aaron Lewis wrote: > > Hi > > > > Below is the profile for kchmviewer, and several changes that should be > > applied to abstractions/kde: > > > hrmm, are we seeing these in other kde pro

[apparmor] abstraction/X doesnt have Xdefaults included?

2013-01-27 Thread Aaron Lewis
Hi, Is there any reason ~/.Xdefaults not included in I think at least, owner @{HOME}/.Xdefaults r, Should be added. -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://pgp.mit.edu/ ) Finger Print: 9482 448F C7C3 896C 1DFE 7DD3 2492 A7D0 DFE6 C29E -- AppArmor mailing list AppArmor

Re: [apparmor] abstraction/X doesnt have Xdefaults included?

2013-01-31 Thread Aaron Lewis
lsfonts?) > > Did you have a denial from a confined application? If so, do you still > have the log messages handy? > > Thanks > -- > AppArmor mailing list > AppArmor@lists.ubuntu.com > Modify settings or unsubscribe at: > https://lists.ubuntu.com/mailman/listinfo/ap

[apparmor] Can't use aa on 3.8.6 kernel!

2013-04-08 Thread Aaron Lewis
atime) -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://keyserver.veridis.com ) Finger Print: 9482 448F C7C3 896C 1DFE 7DD3 2492 A7D0 DFE6 C29E -- AppArmor mailing list AppArmor@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/apparmor

Re: [apparmor] Can't use aa on 3.8.6 kernel!

2013-04-09 Thread Aaron Lewis
Hi John! On 01:38 Tue 09 Apr , John Johansen wrote: > On 04/08/2013 10:57 PM, Aaron Lewis wrote: > > Hi, > > > > I'm running Arch with 3.8.6. kernel, and I got it patched with 2.8.1 > > releases. > > > > But aa-status got errors, > > >

[apparmor] Problems with IPv6

2013-06-24 Thread Aaron Lewis
] type=1400 audit(1372127165.826:1689): apparmor="DENIED" operation="create" parent=11789 profile="/usr/bin/weechat-curses" pid=11791 comm="weechat-curses" family="inet" sock_type="stream" protocol=6 -- Best Regards, Aaron Lewis - PGP:

[apparmor] Using r, w, m, c altogether

2013-06-25 Thread Aaron Lewis
Hi, Looks like I can use rwmc altogether, am I wrong? owner @{HOME}/.config/google-googletalkplugin/{**,} rwmc, -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://keyserver.veridis.com ) Finger Print: 9482 448F C7C3 896C 1DFE 7DD3 2492 A7D0 DFE6 C29E -- AppArmor mailing list AppArmor

Re: [apparmor] Using r, w, m, c altogether

2013-06-26 Thread Aaron Lewis
Ah Thanks I get it now On Wed, Jun 26, 2013 at 8:35 AM, John Johansen wrote: > On 06/25/2013 05:21 PM, Seth Arnold wrote: >> On Wed, Jun 26, 2013 at 07:54:46AM +0800, Aaron Lewis wrote: >>> Hi, >>> >>> Looks like I can use rwmc altogether, am I wrong?

[apparmor] Does compatibility patch support 3.10+ kernel now?

2013-08-03 Thread Aaron Lewis
or profiles has failed) -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://keyserver.veridis.com ) Finger Print: 9482 448F C7C3 896C 1DFE 7DD3 2492 A7D0 DFE6 C29E -- AppArmor mailing list AppArmor@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/apparmor

Re: [apparmor] Does compatibility patch support 3.10+ kernel now?

2013-08-03 Thread Aaron Lewis
Thanks John, I'm going to upgrade the kernel later then. On Sun, Aug 4, 2013 at 2:19 AM, John Johansen wrote: > On 08/03/2013 07:21 AM, Aaron Lewis wrote: >> Hi, >> >> I'm not sure if there's compatibility patch for 3.10+ kernel? >> >> Last time

[apparmor] profiles cannot be deleted

2013-12-20 Thread Aaron Lewis
gentd//null-12 /opt/cisco/anyconnect/bin/vpnagentd//null-13 /opt/cisco/anyconnect/bin/vpnagentd//null-14 I have to reboot to clear them out. -- Best Regards, Aaron Lewis - PGP: 0xDFE6C29E ( http://keyserver.veridis.com ) Finger Print: 9482 448F C7C3 896C 1DFE 7DD3 2492 A7D0 DFE6

Re: [apparmor] profiles cannot be deleted

2013-12-20 Thread Aaron Lewis
Hi John Thanks for the quick reply, I'm going to try that next time I encounter certain situations It seems like if the file gets deleted, the rules became a mess. On Fri, Dec 20, 2013 at 5:45 PM, John Johansen wrote: > On 12/20/2013 01:22 AM, Aaron Lewis wrote: >> Hi, >>

[apparmor] Solutions for scripting files, e.g perl python

2014-01-13 Thread Aaron Lewis
Hi, It looks like one cannot create a profile for a scrit, e.g perl or python Am I wrong? I don't want a single profile for all script that runs by the same interpreter -- Best Regards, Aaron Lewis - PGP: 0x13714D33 - http://pgp.mit.edu/ Finger Print: 9F67 391B B770 8FF6 99DC D92D

[apparmor] Kernel function to disable apparmor

2014-01-15 Thread Aaron Lewis
Hi, I'm not familiar with apparmor implementation, I want to know which function in kernel side can be used to disable apparmor? I'm talking about kernel version 2.6.32 - 3.12, if that matters -- Best Regards, Aaron Lewis - PGP: 0x13714D33 - http://pgp.mit.edu/ Finger Print: 9F67

[apparmor] aa-logprof doesn't check if user is root

2014-01-15 Thread Aaron Lewis
Hi, aa-logprof doesn't check if user is root Can someone add the verification please? just like aa-status and others Thanks! -- Best Regards, Aaron Lewis - PGP: 0x13714D33 - http://pgp.mit.edu/ Finger Print: 9F67 391B B770 8FF6 99DC D92D 87F6 2602 1371 4D33 -- AppArmor mailing

[apparmor] Weird problem with LD_LIBRARY_PATH

2014-05-05 Thread Aaron Lewis
quot; in that profile, anything wrong? That profile is for "/opt/chromium/chromium/chromium", not the script though -- Best Regards, Aaron Lewis - PGP: 0x13714D33 - http://pgp.mit.edu/ Finger Print: 9F67 391B B770 8FF6 99DC D92D 87F6 2602 1371 4D33 -- AppArmor mailing list App

Re: [apparmor] Weird problem with LD_LIBRARY_PATH

2014-05-05 Thread Aaron Lewis
Oops, "When I enforce the opt.chromium.chromium.chromium.sh policy" should be "When I enforce the opt.chromium.chromium.chromium policy" On Tue, May 6, 2014 at 8:40 AM, Aaron Lewis wrote: > Hi, > > I'm trying to setup a chromium profile that is installed in

Re: [apparmor] Weird problem with LD_LIBRARY_PATH

2014-05-07 Thread Aaron Lewis
Too bad, there's no "denied" messages in syslog Not with aa-enforce or aa-complain. Also, I'm running old version of libicuXX.so.VERSION (Arch Linux) On Tue, May 6, 2014 at 1:38 PM, Seth Arnold wrote: > On Tue, May 06, 2014 at 08:40:09AM +0800, Aaron Lewis wrote: >

Re: [apparmor] Weird problem with LD_LIBRARY_PATH

2014-05-07 Thread Aaron Lewis
That old version of libicuXXX does not exists anywhere else On Thu, May 8, 2014 at 10:06 AM, Aaron Lewis wrote: > Too bad, there's no "denied" messages in syslog > > Not with aa-enforce or aa-complain. > > Also, I'm running old version of libicuXX.so.VERSION (

Re: [apparmor] Weird problem with LD_LIBRARY_PATH

2014-05-08 Thread Aaron Lewis
0 gid/egid:1000/1000, parent /usr/bin/bash[bash:29692] uid/euid:1000/1000 gid/egid:1000/1000 On Thu, May 8, 2014 at 10:07 AM, Aaron Lewis wrote: > That old version of libicuXXX does not exists anywhere else > > On Thu, May 8, 2014 at 10:06 AM, Aaron Lewis > wrote:

Re: [apparmor] Weird problem with LD_LIBRARY_PATH

2014-05-19 Thread Aaron Lewis
gt; strace -s 1024 -o strace.out -ff ./chromium.sh Failed to move to new PID namespace: Operation not permitted On Fri, May 9, 2014 at 11:52 AM, John Johansen wrote: > On 05/08/2014 06:01 PM, Aaron Lewis wrote: >> Perhaps I could be restricting /opt/chromium/chromium/chromium.sh ins

Re: [apparmor] Weird problem with LD_LIBRARY_PATH

2014-05-19 Thread Aaron Lewis
Forget to attach the strace.out http://pastebin.mozilla.org/5198979 On Mon, May 19, 2014 at 5:14 PM, Aaron Lewis wrote: > Hmm, That's totally weird. > > I have enabled debugging by executing the two lines you provided > > # aa-complain /etc/apparmor.d/disable/opt.chromium.c

[apparmor] Support binary that might be in different locations?

2014-06-16 Thread Aaron Lewis
Hi, I have a profile that works on /usr/sbin/nginx, is it possible to make it work for /usr/bin/nginx as well? (without a new profile, not even the {} part) I'm not sure if this is supported. -- Best Regards, Aaron Lewis - PGP: 0x13714D33 - http://pgp.mit.edu/ Finger Print: 9F67 391B

[apparmor] What's the 'd' flag?

2014-06-16 Thread Aaron Lewis
nied_mask="d" fsuid=0 ouid=0 I tried to set the 'd' flag in the profile but it caused a syntax error (Running Ubuntu 12.04 everything up-to-date) -- Best Regards, Aaron Lewis - PGP: 0x13714D33 - http://pgp.mit.edu/ Finger Print: 9F67 391B B770 8FF6 99DC D92D 87F6 2602 1

Re: [apparmor] Support binary that might be in different locations?

2014-06-16 Thread Aaron Lewis
Thanks John. What does the second keyword ("nginx" here) in "profile nginx /usr/{s,}bin/nginx" mean? Is it just the profile name, which acts like an ID of the profile perhaps? On Tue, Jun 17, 2014 at 8:28 AM, John Johansen wrote: > On 06/16/2014 05:20 PM, Aaron Lewis wro

Re: [apparmor] What's the 'd' flag?

2014-06-16 Thread Aaron Lewis
Ah I get it, I didn't see the operation="unlink" part back then Thanks John! On Tue, Jun 17, 2014 at 8:31 AM, John Johansen wrote: > On 06/16/2014 05:26 PM, Aaron Lewis wrote: >> Hi, >> >> Take a look at the following message >> >> [ 760.181424]

[apparmor] What's the right way to enforce program in systemd service?

2014-08-11 Thread Aaron Lewis
zed value $ENV{"TERM"} in hash element at /usr/lib/perl5/vendor_perl/Term/ReadLine/Gnu/XS.pm line 371. Aug 06 08:34:36 WIN-QK6JOWSFN7 aa-enforce[2636]: Setting /etc/apparmor.d/usr.sbin.nscd to enforce mode. [ROOT SHELL: ~] -- Best Regards, Aaron Lewis - PGP: 0x13714D33 - http://pgp.mit.

[apparmor] How should one run aa-enforce with systemd?

2014-08-11 Thread Aaron Lewis
still looked annoying -- Best Regards, Aaron Lewis - PGP: 0x13714D33 - http://pgp.mit.edu/ Finger Print: 9F67 391B B770 8FF6 99DC D92D 87F6 2602 1371 4D33 -- AppArmor mailing list AppArmor@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/apparmor

[apparmor] WTF changed in latest aa-enforce?!

2014-08-12 Thread Aaron Lewis
y setuid, network inet stream, /etc/nginx/{,**} r, owner /proc/*/auxv r, /run/nginx.pid rw, /srv/{**,} r, /usr/bin/nginx mr, /usr/share/nginx/{**,} r, /var/html/{**,} r, /var/lib/nginx/fastcgi/{**,} mrw, /var/log/nginx/{*,} w } -- Best Regards, Aaron Lewis - PGP: 0x13714D33 - h

Re: [apparmor] WTF changed in latest aa-enforce?!

2014-08-12 Thread Aaron Lewis
Alright I just saved my application server. Please, TEST your syntax parser before you complete REWRITTEN everything, are you trying to remove the "/path/{,**} rw" syntax? On Wed, Aug 13, 2014 at 12:51 PM, Aaron Lewis wrote: > I just upgraded to Ubuntu 14.04 and every profile I wri

Re: [apparmor] WTF changed in latest aa-enforce?!

2014-08-13 Thread Aaron Lewis
13, 2014 at 12:51:18PM +0800, Aaron Lewis wrote: >> I just upgraded to Ubuntu 14.04 and every profile I write is invalid now, >> WTF? >> Did you guys complete rewritten all script with python? That's really FUNNY > > I'm sorry this failed you. > > Our Perl-bas

Re: [apparmor] WTF changed in latest aa-enforce?!

2014-08-13 Thread Aaron Lewis
; + /foo/bar/baz = True > + /foo/bar/baz/ = True > + /bar/ = False > > Signed-off-by: Seth Arnold > > Thanks > > -- > AppArmor mailing list > AppArmor@lists.ubuntu.com > Modify settings or unsubscribe at: > https://lists.ubuntu.com/mailman/listinfo/appa

Re: [apparmor] What's the right way to enforce program in systemd service?

2014-08-14 Thread Aaron Lewis
> AppArmor mailing list > AppArmor@lists.ubuntu.com > Modify settings or unsubscribe at: > https://lists.ubuntu.com/mailman/listinfo/apparmor -- Best Regards, Aaron Lewis - PGP: 0x13714D33 - http://pgp.mit.edu/ Finger Print: 9F67 391B B770 8FF6 99DC D92D 87F6 2602 1371 4D33 -- AppArmor mailing list AppArmor@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/apparmor