Re: [apparmor] [patch] nscd profile: allow reading libvirt/dnsmasq/*.status

2016-12-08 Thread Seth Arnold
On Thu, Dec 08, 2016 at 02:58:51PM +0100, Christian Boltz wrote: > Hello, > > $subject. > > References: https://bugzilla.opensuse.org/show_bug.cgi?id=1014463 > > > I propose this patch for trunk, 2.10 and 2.9. > > > [ nscd-libvirt.diff ] Acked-by: Seth Arnold Acked for all three. Thanks

[apparmor] [patch] nscd profile: allow reading libvirt/dnsmasq/*.status

2016-12-08 Thread Christian Boltz
Hello, $subject. References: https://bugzilla.opensuse.org/show_bug.cgi?id=1014463 I propose this patch for trunk, 2.10 and 2.9. [ nscd-libvirt.diff ] === modified file 'profiles/apparmor.d/usr.sbin.nscd' --- profiles/apparmor.d/usr.sbin.nscd 2016-11-18 19:17:43 + +++ profiles/apparmor

Re: [apparmor] [patch] nscd profile: allow paranoia mode

2016-03-21 Thread Jamie Strandboge
On Mon, 2016-03-21 at 21:01 +0100, Christian Boltz wrote: > Hello, > > in /etc/nscd.conf there is an option allowing to restart nscd after a > certain time. However, this requires reading /proc/self/cmdline - > otherwise nscd will disable paranoia mode. > > > References: https://bugzilla.opensus

[apparmor] [patch] nscd profile: allow paranoia mode

2016-03-21 Thread Christian Boltz
Hello, in /etc/nscd.conf there is an option allowing to restart nscd after a certain time. However, this requires reading /proc/self/cmdline - otherwise nscd will disable paranoia mode. References: https://bugzilla.opensuse.org/show_bug.cgi?id=971790 I propose this patch for trunk, 2.10 and 2.

Re: [apparmor] [patch] nscd profile

2013-03-05 Thread Seth Arnold
On Tue, Mar 05, 2013 at 07:25:46PM +0100, Christian Boltz wrote: > Hello, > > the following patch is the result of last night's discussion on IRC. > (Well, at least for me it was night ;-) > > > I propose this patch for trunk and the 2.8 branch. > > > Add missing permissions to the nscd profil

[apparmor] [patch] nscd profile

2013-03-05 Thread Christian Boltz
Hello, the following patch is the result of last night's discussion on IRC. (Well, at least for me it was night ;-) I propose this patch for trunk and the 2.8 branch. Add missing permissions to the nscd profile. Also deny capability block_suspend because nobody can imagine why it would be ne