Re: [apparmor] Let's enable AppArmor by default (why not?)

2018-03-20 Thread Christian Boltz
Hello, Am Dienstag, 20. März 2018, 01:37:03 CET schrieb Seth Arnold: > On Mon, Mar 19, 2018 at 10:10:02AM -0400, Marvin Renich wrote: > > Is there a way that an app (e.g. smbd) whose file access > > requirements > > change dynamically through admin and user configuration can at least > > inspect i

Re: [apparmor] Let's enable AppArmor by default (why not?)

2018-03-19 Thread Seth Arnold
On Mon, Mar 19, 2018 at 10:10:02AM -0400, Marvin Renich wrote: > Is there a way that an app (e.g. smbd) whose file access requirements > change dynamically through admin and user configuration can at least > inspect its own apparmor profile and give the user a clue that the admin > must update the

Re: [apparmor] Let's enable AppArmor by default (why not?)

2018-03-19 Thread Mathieu Parent
Hi, Samba maintainer here ... 2018-03-19 15:10 GMT+01:00 Marvin Renich : [...] > As a side note, my laptop runs testing, and I allowed apparmor to be > enabled when that change hit testing. The only issue I have noticed so > far is that smbd would not have access to some (intentionally public,

Re: [apparmor] Let's enable AppArmor by default (why not?)

2018-03-19 Thread Marvin Renich
[added d-dev back] * intrigeri [180319 07:40]: > Marvin Renich: > > Actually, a short beginner's guide as a text file in > > /usr/share/doc/apparmor, which has more than just "how to disable a > > profile" would be extremely helpful. I don't have the apparmor > > knowledge to write it, though. >

Re: [apparmor] Let's enable AppArmor by default (why not?)

2017-11-20 Thread Wouter Verhelst
On Mon, Nov 20, 2017 at 07:01:29PM +0100, intrigeri wrote: > Wouter Verhelst: > > It would be awesome if you could also include some documentation in the > > style "I'm a Debian package maintainer and the apparmor profile for some > > of the binaries in one of my packages is buggy, how can I fix it

Re: [apparmor] Let's enable AppArmor by default (why not?)

2017-11-20 Thread intrigeri
Wouter Verhelst: > It would be awesome if you could also include some documentation in the > style "I'm a Debian package maintainer and the apparmor profile for some > of the binaries in one of my packages is buggy, how can I fix it?" > or "I'm a Debian package maintainer and I'd like to write an >

Re: [apparmor] Let's enable AppArmor by default (why not?)

2017-11-19 Thread Wouter Verhelst
On Sat, Nov 18, 2017 at 07:23:42PM -0800, John Johansen wrote: > On 11/18/2017 01:59 PM, Marvin Renich wrote: > > * John Johansen [171118 16:02]: > >> You can disable individual profiles without editing them and messing up > >> the packaging by using aa-disable > > [some really good beginner stuf

Re: [apparmor] Let's enable AppArmor by default (why not?)

2017-11-18 Thread John Johansen
On 11/18/2017 01:59 PM, Marvin Renich wrote: > * John Johansen [171118 16:02]: >> You can disable individual profiles without editing them and messing up the >> packaging by using aa-disable > [some really good beginner stuff snipped] > > John, many thanks for these tidbits. Can they be put in

Re: [apparmor] Let's enable AppArmor by default (why not?)

2017-11-18 Thread Marvin Renich
* John Johansen [171118 16:02]: > You can disable individual profiles without editing them and messing up the > packaging by using aa-disable [some really good beginner stuff snipped] John, many thanks for these tidbits. Can they be put in a text file in /usr/share/doc/apparmor, with a NEWS.Deb

Re: [apparmor] Let's enable AppArmor by default (why not?)

2017-11-18 Thread John Johansen
On 11/17/2017 05:34 PM, Ben Caradoc-Davies wrote: > On 18/11/17 04:27, intrigeri wrote: >> Thanks in advance, and sorry for any inconvenience it may cause (e.g. >> the AppArmor policy for Thunderbird has various issues in sid; all of >> those I'm aware of are fixed in experimental already). > > Wh