Re: [apparmor] Let's enable AppArmor by default (why not?)

2017-11-18 Thread John Johansen
On 11/18/2017 01:59 PM, Marvin Renich wrote: > * John Johansen [171118 16:02]: >> You can disable individual profiles without editing them and messing up the >> packaging by using aa-disable > [some really good beginner stuff snipped] > > John, many thanks for these tidb

Re: [apparmor] Let's enable AppArmor by default (why not?)

2017-11-18 Thread John Johansen
On 11/17/2017 05:34 PM, Ben Caradoc-Davies wrote: > On 18/11/17 04:27, intrigeri wrote: >> Thanks in advance, and sorry for any inconvenience it may cause (e.g. >> the AppArmor policy for Thunderbird has various issues in sid; all of >> those I'm aware of are fixed in experimental already). > > Wh

Re: Let's enable AppArmor by default (why not?)

2017-09-09 Thread John Johansen
On 09/09/2017 12:49 PM, intrigeri wrote: > Hi John et al, > > John Johansen: >> On 08/09/2017 02:31 PM, intrigeri wrote: >>> Moritz Mühlenhoff: >>>> Christian Seiler schrieb: >>>>> Another thing to consider: if a profile is too restrictive, but

Re: Let's enable AppArmor by default (why not?)

2017-08-10 Thread John Johansen
On 08/10/2017 02:23 PM, Simon McVittie wrote: > On Thu, 10 Aug 2017 at 12:00:15 -0700, John Johansen wrote: >> but ideally would be enabled by the dbus code advising the >> kernel module it is mediating > > "The" dbus code? There can be several parallel insta

Re: Let's enable AppArmor by default (why not?)

2017-08-10 Thread John Johansen
On 08/10/2017 11:31 AM, Simon McVittie wrote: > On Wed, 09 Aug 2017 at 17:17:17 -0700, John Johansen wrote: >> The dbus code went through several revisions as well. While the dbus >> code doesn't require a lot from the kernel, it did have some influence >> on the

Re: Let's enable AppArmor by default (why not?)

2017-08-09 Thread John Johansen
On 08/09/2017 02:31 PM, intrigeri wrote: > Hi, > > [John, there's a question for you at the bottom, but you probably have > useful input about the first part of the discussion below too.] > > Moritz Mühlenhoff: >> Christian Seiler schrieb: >>> Another thing to consider: if a profile is too restr