Re: [apparmor] Learning apparmor

2012-12-18 Thread Jamie Strandboge
On 12/17/2012 05:29 PM, Christian Boltz wrote: Besides that, John forgot to mention Ux, Px and Cx (and Pix, Cix and PUx). They basically do the same as their lowercase counterparts, but are more secure because they clean the environment variables (LD_PRELOAD, PATH etc.) before executing

Re: [apparmor] Learning apparmor

2012-12-18 Thread John Johansen
On 12/18/2012 09:31 AM, Diane Trout wrote: Thank you for the quite detailed response to my first questions. Can you have overlaping rules in one file? within a profile overlapping rules have their permissions merged for the parts of the rules that overlap, except for exec qualifiers where

Re: [apparmor] Learning apparmor

2012-12-17 Thread John Johansen
On 12/16/2012 08:11 PM, Diane Trout wrote: Hi, I was trying to wrap a third-party application using apparmor and had a few questions. (I was trying to wrap http://spectrum.im, I put my experimental profiles at https://github.com/detrout/apparmor-det) 1) Are there common patterns for

[apparmor] Learning apparmor

2012-12-16 Thread Diane Trout
Hi, I was trying to wrap a third-party application using apparmor and had a few questions. (I was trying to wrap http://spectrum.im, I put my experimental profiles at https://github.com/detrout/apparmor-det) 1) Are there common patterns for letting manager program control its children? As I