[Bug 2111845] Re: autopkgtests failing with fuse3 3.17

2025-06-13 Thread Georgia Garcia
** Changed in: apparmor (Ubuntu) Assignee: (unassigned) => Georgia Garcia (georgiag) ** Changed in: apparmor (Ubuntu) Status: New => Fix Committed ** Changed in: apparmor (Ubuntu) Status: Fix Committed => In Progress -- You received this bug notification because

[Bug 2111845] Re: autopkgtests failing with fuse3 3.17

2025-06-12 Thread Georgia Garcia
I'd like to note that I tested all packages that are currently failing in the update excuses page and fuseiso is not failing because of the fusermount3 profile. The following test still fails when the profile is removed. autopkgtest fuseiso -U --shell-fail --setup-commands="sudo apparmor_parser -R

[Bug 2111845] Re: autopkgtests failing with fuse3 3.17

2025-06-11 Thread Georgia Garcia
Created a MR upstream with a tentative fix in https://gitlab.com/apparmor/apparmor/-/merge_requests/1716 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2111845 Title: autopkgtests failing with fuse3

[Bug 2098993] Re: Last updates to apparmor broke all AppImages, which depend on fusermount

2025-06-02 Thread Georgia Garcia
Hi Sofie. I'm sorry this has been happening. Could you check your system logs for any apparmor DENIED messages? You can run this command in your terminal: journalctl -b | grep DENIED | grep fusermount or sudo dmesg | grep DENIED | grep fusermount -- You received this bug notification because y

[Bug 2098993] Re: Last updates to apparmor broke all AppImages, which depend on fusermount

2025-05-27 Thread Georgia Garcia
Hi Khairul, Could you check your system logs for apparmor DENIED messages? The relevant ones likely have profile=“fusermount3” in them. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2098993 Title:

[Bug 2111478] Re: docker fails to run in CIS hardened Ubuntu Server

2025-05-26 Thread Georgia Garcia
Since noble there are unconfined profiles which are part of the unprivileged user namespace restriction. There is a CIS Level 2 rule that requires all AppArmor profiles to be in enforce mode, which at the moment includes the unconfined profiles. There is ongoing discussion with the CIS community [1

[Bug 2111604] Re: lsblk: failed to get sysfs name: Permission denied

2025-05-23 Thread Georgia Garcia
Hi Christian. The patch looks good to me. Do you mind submitting it to the apparmor project upstream? https://gitlab.com/apparmor/apparmor under profiles/apparmor.d/lsblk If possible, please include a link to this bug in the commit message -- You received this bug notification because you are a

[Bug 2077336] Re: Creation of armv7l vm fails due to tpm-tis

2025-04-04 Thread Georgia Garcia
Verification completed successfully with domain being created as expected: root@sec2-jammy-amd64:~# apt install qemu qemu-kvm qemu-system-arm libvirt-clients libvirt-daemon-system virtinst bridge-utils Reading package lists... Done Building dependency tree... Done Reading state information... Don

[Bug 2105986] Re: Apparmor parser 2.12 doesn't find kernel feature that is a substring of another that appears first in search algorithm

2025-04-02 Thread Georgia Garcia
ned) => Georgia Garcia (georgiag) ** Changed in: apparmor (Ubuntu) Importance: Undecided => Critical -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2105986 Title: Apparmor parser 2.12 doesn'

[Bug 2100015] Re: apparmor breaks flatpak and firejail

2025-02-28 Thread Georgia Garcia
I could reproduce this issue on linux 6.12 but plucky is soon moving to 6.14 in which this is no longer reproducible. ** Changed in: apparmor (Ubuntu) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

[Bug 2100015] Re: apparmor breaks flatpak and firejail

2025-02-27 Thread Georgia Garcia
** Changed in: apparmor (Ubuntu) Assignee: (unassigned) => Georgia Garcia (georgiag) ** Changed in: apparmor (Ubuntu) Status: New => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchp

[Bug 2067900] Re: apparmor unconfined profile blocks pivot_root

2025-02-27 Thread Georgia Garcia
Hi The Owl, my apologies. I updated the description containing the SRU justification with the thorough testing steps. Here's the correct verification: root@sec-oracular-amd64:~# lxc launch ubuntu:24.10 test -c security.nesting=true Launching test root@sec-oracular-amd64:~# lxc exec test bash root

[Bug 2067900] Re: apparmor unconfined profile blocks pivot_root

2025-02-27 Thread Georgia Garcia
Verification completed in oracular linux/6.11.0-21.21. Works as expected. georgia@sec-oracular-amd64:~$ uname -a Linux sec-oracular-amd64 6.11.0-21-generic #21-Ubuntu SMP PREEMPT_DYNAMIC Wed Feb 19 16:50:40 UTC 2025 x86_64 x86_64 x86_64 GNU/Linux georgia@sec-oracular-amd64:~$ sudo lxc launch ubu

[Bug 2095370] Re: AppArmor early policy load not funcitoning

2025-02-27 Thread Georgia Garcia
Verification completed on oracular linux/6.11.0-21.21 georgia@sec-oracular-amd64:~$ uname -a Linux sec-oracular-amd64 6.11.0-21-generic #21-Ubuntu SMP PREEMPT_DYNAMIC Wed Feb 19 16:50:40 UTC 2025 x86_64 x86_64 x86_64 GNU/Linux georgia@sec-oracular-amd64:~$ journalctl -b | grep systemd | grep -i

[Bug 2077336] Re: Creation of armv7l vm fails due to tpm-tis

2025-02-26 Thread Georgia Garcia
Hi Bryce, yes I'm able to help with testing. I was able to reproduce the issue on a virtualized jammy using my tpm device as passthrough (I had to manually add apparmor permission to access /dev/tpm* rw, though... another bug). And I was also able to verify that the version from Sergio's PPA works

[Bug 2098838] Re: apparmor appears to deny wpasupplicant on plucky, breaking wifi

2025-02-24 Thread Georgia Garcia
Hi Heinrich. Did you try rebooting after upgrading to 4.1.0~beta5-0ubuntu5? The profile could still be loaded in the kernel thus enforcing restrictions unless rebooting or manually unloading the profile. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subs

[Bug 2098838] Re: apparmor appears to deny wpasupplicant on plucky, breaking wifi

2025-02-21 Thread Georgia Garcia
Hi Dave There's a new apparmor_4.1.0~beta5-0ubuntu5 available in plucky-proposed that should remove the wpa_supplicant apparmor profile. We decided to disable it by default for now in Ubuntu I added a comment in the upstream MR for the profile fix, feel free to add more details there if you wish

[Bug 2098929] Re: new mbsync profile doesn't work when .mbsyncrc is symlinked

2025-02-20 Thread Georgia Garcia
Hi Thomas, thanks for the report AppArmor resolves the symbolic link on mediation, so to allow mbsync to access those files, you can add the following permission to /etc/apparmor.d/local/mbsync @{HOME}/dotfiles/isync/.mbsyncrc r, It can be done by the following command: sudo bash -c "echo '@{HO

[Bug 2098838] Re: apparmor appears to deny wpasupplicant on plucky, breaking wifi

2025-02-20 Thread Georgia Garcia
Hi Khairul. Unfortunately the fix was not complete and there's a 4.1.0~beta5-0ubuntu5 on the way. What you can do now is unload the profile and remove it. # apparmor_parser --remove /etc/apparmor.d/wpa_supplicant # rm /etc/apparmor.d/wpa_supplicant -- You received this bug notification because

[Bug 2098930] Re: openvpn profile doesn't allow access to files on home dir

2025-02-20 Thread Georgia Garcia
hi Thomas To allow access to these files, you can add the following rule to /etc/apparmor.d/local/openvpn: @{HOME}/Documents/canonical/vpn/canonical_ta.key r, It can be done by the following command: sudo bash -c "echo '@{HOME}/Documents/canonical/vpn/canonical_ta.key r,' >> /etc/apparmor.d/loc

[Bug 2095370] Re: AppArmor early policy load not funcitoning

2025-02-20 Thread Georgia Garcia
Verification completed on noble kernel 6.8.0-56.58: $ journalctl -b | grep systemd | grep -i apparmor ... Feb 20 09:50:03 sec3-noble-amd64 kernel: audit: type=1400 audit(1740055803.156:9): apparmor="STATUS" operation="profile_load" profile="unconfined" name="busybox" pid=1 comm="systemd" Feb 20

[Bug 481661] Re: Add Google Chrome to ubuntu-browsers

2025-02-19 Thread Georgia Garcia
Hi Fred, I'm sorry to hear that things are not working as you expect. If you can, could you open a new bug here on launchpad or in the upstream apparmor repo https://gitlab.com/apparmor/apparmor/-/issues containing the details of what's not working for you? It would be very helpful if you could inc

[Bug 2077336] Re: Creation of armv7l vm fails due to tpm-tis

2025-02-19 Thread Georgia Garcia
hi Lukas. Yes, I was reproducing it on my host with real hardware. Unfortunately I have since upgraded to noble, so I'm unable to test unless I downgrade the packages (let me know if you'd like me to) Regarding TPM, I'm not sure what to look for, but here's what I got $ cat /sys/class/tpm/tpm0/t

[Bug 481661] Re: Add Google Chrome to ubuntu-browsers

2025-02-18 Thread Georgia Garcia
Hi Fred, What is the output of "realpath /usr/bin/google-chrome" in our machine? Here I have $ realpath /usr/bin/google-chrome /opt/google/chrome/google-chrome which is already covered by the rule /opt/google/chrome{,-beta,-unstable}/google-chrome{,-beta,-unstable} Cx -> sanitized_helper, App

[Bug 2098148] Re: Cannot log to bindmounted syslog socket within a container due to rsyslogd profile

2025-02-13 Thread Georgia Garcia
Since rsyslog ships its own apparmor profile, I'm adding rsyslog as the affected package and marking apparmor as invalid. ** Also affects: rsyslog (Ubuntu) Importance: Undecided Status: New ** Changed in: apparmor Status: New => Invalid -- You received this bug notification bec

[Bug 2095370] Re: AppArmor early policy load not funcitoning

2025-01-28 Thread Georgia Garcia
** Description changed: + SRU Justification: + + [Impact] + + The commit being reverted allows the use of runtime information on + AppArmor features, usually located under + /sys/kernel/security/apparmor/features/ + + The set of features is used to calculate the features' hash, used by + AppArm

[Bug 2095370] Re: AppArmor early policy load not funcitoning

2025-01-23 Thread Georgia Garcia
The bug was caused by a commit [1] in the Ubuntu kernel that would change the kernel features hash based on the status of the userns and io_uring restriction. When the policy cache was generated, userns restriction would be available and the hash under /etc/apparmor/earlypolicy/ would match the set

[Bug 2047256] Re: Ubuntu 24.04 Some image thumbnails no longer displayed

2024-12-11 Thread Georgia Garcia
Hi Eugenio. I'm relieved to hear that you are using Desktop Icons NG. That bug is being tracked in https://bugs.launchpad.net/ubuntu/+source/gnome-shell-extension-desktop-icons-ng/+bug/2064849 as kanschat shared in #41 Good news is that there's already a fix on the way https://salsa.debian.org

[Bug 2047256] Re: Ubuntu 24.04 Some image thumbnails no longer displayed

2024-12-11 Thread Georgia Garcia
Hi Eugenio. I appreciate your patience, but we haven't been able to reproduce the issue so we depend on our logs to draw out any conclusion. Is there any change you are using a different software or extension to display your thumbnails other than nautilus directly? Something like gnome-shell-exten

[Bug 2089378] Re: bwrap needs an apparmor profile to work

2024-11-22 Thread Georgia Garcia
This profile bypasses the restriction of unprivileged user namespaces, therefore Ubuntu cannot ship it, and we recommend you don't use it as well. If an application calls bwrap with a valid use of unpriv userns, then a profile for that app should be created instead. Let me know if you need any help

[Bug 2079019] Re: Unable to enforce/disable profiles using aa-enforce/aa-disable

2024-11-13 Thread Georgia Garcia
This is the fix upstream: https://gitlab.com/apparmor/apparmor/-/merge_requests/1237/diffs?commit_id=1f4bba0448563b7d1fe4d86c230556ebf8d3805b -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2079019 Tit

[Bug 2047256] Re: Ubuntu 24.04 Some image thumbnails no longer displayed

2024-11-07 Thread Georgia Garcia
Eugenio, do you see any apparmor messages in your system logs? They could be in /var/log/syslog or /var/log/kern.log, or if you have auditd installed /var/log/audit/audit.log -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs

[Bug 2064672] Re: [SRU] - fixes for apparmor on noble

2024-11-07 Thread Georgia Garcia
You will need to create an AppArmor profile for the AppImage to work using unprivileged user namespaces with privileged operations. Here's a more detailed explanation in a different bug: https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2056627/comments/4 -- You received this bug notificati

[Bug 2047256] Re: Ubuntu 24.04 Some image thumbnails no longer displayed

2024-10-29 Thread Georgia Garcia
If after running the following command thumbnails still won't load, then it is not related to this bug report. If that's the case, please open a new bug. sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 Note that this makes your setup vulnerable, so I recommend turning back on afte

[Bug 2046844] Re: AppArmor user namespace creation restrictions cause many applications to crash with SIGTRAP

2024-10-24 Thread Georgia Garcia
Hi Ondra. Could you share what the apparmor profile looks like? Spaces should work when surrounded by double quotes in the profile. In 4.0.1really4.0.1-0ubuntu0.24.04.3 there's an example of that in /etc/apparmor.d/MongoDB_Compass. profile "MongoDB Compass" "/usr/lib/mongodb-compass/MongoDB Compas

[Bug 2085377] Re: transmission-gtk fails to start in separate network namespace

2024-10-22 Thread Georgia Garcia
Hi Janne, thanks for reporting. Adding attach_disconnected to the profile flags is the correct course of action at this point. I submitted a MR upstream with the information you provided: https://gitlab.com/apparmor/apparmor/-/merge_requests/1395 -- You received this bug notification because y

[Bug 2084008] Re: aa-complain: TypeError: 'NoneType' object is not callable

2024-10-09 Thread Georgia Garcia
Hi! Thank you for reporting this issue. It was already fixed by upstream AppArmor but the fix still needs to be applied in the apparmor package: https://gitlab.com/apparmor/apparmor/-/merge_requests/1218 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subsc

[Bug 2039294] Re: apparmor docker

2024-10-04 Thread Georgia Garcia
** Attachment added: "docker-default" https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2039294/+attachment/5824926/+files/docker-default -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2039294

[Bug 2067900] Re: apparmor unconfined profile blocks pivot_root

2024-10-03 Thread Georgia Garcia
Hi, mihalicyn, sorry for the delay answering. That's unfortunately right. Ubuntu 12.04 ships apparmor 2.7 which didn't have support for ABIs yet, so dc757a645cfa82f6ac252365df20a36a9ff82760 causes a regression on those early versions. I talked to @jjohansen and we have agreed that this patch needs

[Bug 2072702] Re: AppArmor profile prevents use of TLS keys and certificates

2024-10-03 Thread Georgia Garcia
I agree that if /etc/ipa/ca.crt is a standard location for that package (which appears to be https://pagure.io/freeipa/blob/master/f/ipaplatform/base/paths.py#_69) then we could add it to the ssl_certs abstraction -- You received this bug notification because you are a member of Ubuntu Bugs, whic

[Bug 2083435] Re: AppArmor 4.1.0-beta1 contains an ABI break for aa_log_record

2024-10-01 Thread Georgia Garcia
** Also affects: apparmor (Ubuntu) Importance: Undecided Status: New ** No longer affects: apparmor (Ubuntu) ** Also affects: apparmor (Ubuntu) Importance: Undecided Status: New ** Also affects: apparmor (Ubuntu Oracular) Importance: Undecided Status: New -- You r

[Bug 2073661] Re: nordvpn generates many ip6 warnng messages

2024-09-11 Thread Georgia Garcia
It does seem to be an issue with their snap apparmor policy, which they manage directly. Feel free to report the issue to them directly https://github.com/NordSecurity/nordvpn-linux ** Changed in: apparmor (Ubuntu) Status: New => Invalid -- You received this bug notification because you a

[Bug 2074068] Re: Squashfs image uses (null) compression, this version supports only xz, zlib.

2024-09-11 Thread Georgia Garcia
From the comments in the forum, it seems that the AppImage was corrupted. Since it doesn't seem apparmor related, I'm setting this bug as Invalid. Feel free to change back it if you don't agree. ** Changed in: apparmor (Ubuntu) Status: Confirmed => Invalid -- You received this bug notific

[Bug 2074277] Re: my network wifi and land have a very bad working

2024-09-11 Thread Georgia Garcia
Hi! Could you add some logs so we can determine if it's apparmor related? You can run the following command to get them automatically. apport-collect -p apparmor 2074277 ** Changed in: apparmor (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a mem

[Bug 2067900] Re: apparmor unconfined profile blocks pivot_root

2024-09-11 Thread Georgia Garcia
Sorry for the delay. The fix had landed but it was reverted due to a regression. We have a 4.0.1really4.0.1-0ubuntu0.24.04.3 update but it is still sitting in noble-proposed https://people.canonical.com/~ubuntu-archive/pending-sru.html -- You received this bug notification because you are a

[Bug 2077336] Re: Creation of armv7l vm fails due to tpm-tis

2024-09-06 Thread Georgia Garcia
Ah, I tested only in jammy amd64. Here's my setup: georgia@georgia:~$ lsb_release -a No LSB modules are available. Distributor ID: Ubuntu Description:Ubuntu 22.04.4 LTS Release:22.04 Codename: jammy georgia@georgia:~$ uname -a Linux georgia 5.15.0-119-generic #129-Ubuntu SMP Fri

[Bug 2077336] Re: Creation of armv7l vm fails due to tpm-tis

2024-09-05 Thread Georgia Garcia
Hi Sergio The version from the PPA fixes it for me. Thank you for working on this! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2077336 Title: Creation of armv7l vm fails due to tpm-tis To manage

[Bug 2078467] Re: aa-enforce /etc/apparmor.d/* - Error

2024-08-30 Thread Georgia Garcia
Hi appe! There's a new version of apparmor in the noble-proposed pocket that should fix this issue: https://launchpad.net/ubuntu/+source/apparmor/4.0.1really4.0.1-0ubuntu0.24.04.3 https://wiki.ubuntu.com/Testing/EnableProposed -- You received this bug notification because you are a member of U

[Bug 2039294] Re: apparmor docker

2024-08-27 Thread Georgia Garcia
@lazka: you can use this profile: https://pastebin.canonical.com/p/VbmH97Rhqp/ I grabbed it from upstream: https://github.com/moby/moby/blob/master/profiles/apparmor/template.go Note that for the rule "signal (receive) peer={{.DaemonProfile}}," in the template I assumed the DaemonProfile is unco

[Bug 2046844] Re: AppArmor user namespace creation restrictions cause many applications to crash with SIGTRAP

2024-08-22 Thread Georgia Garcia
Verification completed in bug 2064672 ** Tags removed: verification-needed verification-needed-noble ** Tags added: verification-done verification-done-noble -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/b

[Bug 2056297] Re: Non-flatpak Firefox-based browsers crash with kernel 6.8.0-11-generic in 24.04

2024-08-22 Thread Georgia Garcia
*** This bug is a duplicate of bug 2046844 *** https://bugs.launchpad.net/bugs/2046844 Verification completed in bug 2064672 ** Tags removed: verification-needed verification-needed-noble ** Tags added: verification-done verification-done-noble -- You received this bug notification because

[Bug 2060100] Re: denials from sshd in noble

2024-08-22 Thread Georgia Garcia
Verification completed in bug 2064672 ** Tags removed: verification-needed verification-needed-noble ** Tags added: verification-done verification-done-noble -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/b

[Bug 2072811] Re: Apparmor: New update broke flatpak with `apparmor="DENIED"`

2024-08-22 Thread Georgia Garcia
Verification completed in bug 2064672 ** Tags removed: verification-needed verification-needed-noble ** Tags added: verification-done verification-done-noble -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/b

[Bug 2047256] Re: Ubuntu 24.04 Some image thumbnails no longer displayed

2024-08-20 Thread Georgia Garcia
Ah, so it's not the same issue as the original bug report, it's something else. Since it's not related to apparmor, I recommend you open a new bug here in launchpad or upstream https://gitlab.gnome.org/GNOME/nautilus/-/issues so other people can help you debug and hopefully fix this issue. -- You

[Bug 2064672] Re: [SRU] - fixes for apparmor on noble

2024-08-20 Thread Georgia Garcia
Verification completed on apparmor noble-proposed $ apt policy apparmor apparmor: Installed: 4.0.1really4.0.1-0ubuntu0.24.04.3 Candidate: 4.0.1really4.0.1-0ubuntu0.24.04.3 Version table: *** 4.0.1really4.0.1-0ubuntu0.24.04.3 100 100 http://archive.ubuntu.com/ubuntu noble-proposed/ma

[Bug 2077413] Re: apparmor unconfined profile blocks signal sending

2024-08-20 Thread Georgia Garcia
I have noticed that a lot of AppArmor policies use peer=unconfined when they meant *any* peer. I believe this is also the case for bug 2040483. I see little difference in allowing "signal (receive) peer=unconfined," vs "signal (receive)," in abstractions/base, so I proposed https://gitlab.com/appa

[Bug 2077336] Re: Creation of armv7l vm fails due to tpm-tis

2024-08-19 Thread Georgia Garcia
** Description changed: I downloaded an armhf cloud image on jammy and tried to create a vm but - I got an error saying that tpm-this is not supported + I got an error saying that tpm-tis is not supported $ wget https://cloud-images.ubuntu.com/oracular/current/oracular-server-cloudimg-armh

[Bug 2077336] [NEW] Creation of armv7l vm fails due to tpm-tis

2024-08-19 Thread Georgia Garcia
Public bug reported: I downloaded an armhf cloud image on jammy and tried to create a vm but I got an error saying that tpm-this is not supported $ wget https://cloud-images.ubuntu.com/oracular/current/oracular-server-cloudimg-armhf.img $ sudo virt-install -n oracular-arm --os-variant=generic

[Bug 2077158] Re: /etc/apparmor.d/usr.bin.pasta is missing in Ubuntu's apparmor package

2024-08-16 Thread Georgia Garcia
Since the profile is not shipped by the apparmor package, I'm marking it as invalid and adding the correct package passt ** Also affects: passt (Ubuntu) Importance: Undecided Status: New ** Changed in: apparmor (Ubuntu) Status: New => Invalid -- You received this bug notificati

[Bug 2047256] Re: Ubuntu 24.04 Some image thumbnails no longer displayed

2024-07-29 Thread Georgia Garcia
The main issue is that I still wasn't able to reproduce it locally. Dan, could you check if this issue still happens with the unprivileged user namespace restriction disabled? sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 Please note that this makes your setup vulnerable, so I r

[Bug 2064672] Re: [SRU] - fixes for apparmor on noble

2024-07-18 Thread Georgia Garcia
I have updated the description with the information of the SRU version 4.0.1really4.0.1-0ubuntu0.24.04.3 The Test Plan is updated with detailed instructions and I also added an analysis of why the regression happened for the previous SRU. Note that since we have removed the enablement by default

[Bug 2065915] Re: [SRU] Add multiarch lines for each architecture we want to support in our apparmor profiles.

2024-07-18 Thread Georgia Garcia
As I understand these changes are only waiting to be sponsored to proposed, correct? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2065915 Title: [SRU] Add multiarch lines for each architecture we w

[Bug 2072811] Re: Apparmor: New update broke flatpak with `apparmor="DENIED"`

2024-07-16 Thread Georgia Garcia
Here's my proposed fix for oracular. It disables the bwrap profile so we can do further tests. As was done on noble, it does require a reboot. It's also available on this ppa: https://launchpad.net/~georgiag/+archive/ubuntu/4.0.1-0ubuntu2 ** Patch added: "apparmor_4.0.1-0ubuntu2.debdiff" ht

[Bug 2072811] Re: Apparmor: New update broke flatpak with `apparmor="DENIED"`

2024-07-16 Thread Georgia Garcia
@Robie Basak: I ran QRT and the tests passed: georgia@ubuntu:~/qrt-test-apparmor$ sudo ./install-packages test-apparmor.py georgia@ubuntu:~/qrt-test-apparmor$ sudo ./test-apparmor.py ... -- Ran 62 tests in 1974.585s OK (skippe

[Bug 2065915] Re: [SRU] Add multiarch lines for each architecture we want to support in our apparmor profiles.

2024-07-10 Thread Georgia Garcia
Hi Scarlett, No worries, that log should be enough to understand what's going on. That is a bug in the snapd interface because the AppArmor policy specified the peer_label as unconfined, but that's no longer the case for plasmashell. I'll reach out to the snapd team and report the issue. Thank

[Bug 2072615] Re: Request to add a default profile for bitbake

2024-07-10 Thread Georgia Garcia
Hi Changqing Li, Thanks for your report. Unfortunately, as John has stated in this comment: https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2063976/comments/3 We are not able to ship a profile for bitbake running in a writable location of an unprivileged user because it could be used to b

[Bug 2065915] Re: [SRU] Fix hard coded path in apparmor profiles.

2024-07-09 Thread Georgia Garcia
As per the discussion in https://irclogs.ubuntu.com/2024/07/09/%23ubuntu-security.txt The recommendation from the security team is to not revert to the "flags=(unconfined)" profile if the profile is already confined. That means that we should only fix the multiarch issue. Scarlett, you're right

[Bug 2062138] Re: test-logprof.py from test_utils_testsuite / test_utils_testsuite3 in ubuntu_qrt_apparmor failing on Azure Standard_A2_v2

2024-07-09 Thread Georgia Garcia
Added to QRT in MR https://code.launchpad.net/~georgiag/qa-regression- testing/+git/qa-regression-testing/+merge/468941 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2062138 Title: test-logprof.py f

[Bug 2032602] Re: [FFe] apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in mantic

2024-07-09 Thread Georgia Garcia
** Tags removed: verification-needed-jammy-linux-lowlatency-hwe-6.8 ** Tags added: verification-done-jammy-linux-lowlatency-hwe-6.8 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2032602 Title: [FFe]

[Bug 2056297] Re: Non-flatpak Firefox-based browsers crash with kernel 6.8.0-11-generic in 24.04

2024-07-08 Thread Georgia Garcia
*** This bug is a duplicate of bug 2046844 *** https://bugs.launchpad.net/bugs/2046844 Verification done as part of Bug 2064672 ** Tags removed: verification-needed verification-needed-noble ** Tags added: verification-done verification-done-noble -- You received this bug notification becau

[Bug 2046844] Re: AppArmor user namespace creation restrictions cause many applications to crash with SIGTRAP

2024-07-08 Thread Georgia Garcia
Verification done as part of Bug 2064672 ** Tags removed: verification-needed verification-needed-noble ** Tags added: verification-done verification-done-noble -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.ne

[Bug 2060100] Re: denials from sshd in noble

2024-07-08 Thread Georgia Garcia
Verification done as part of Bug 2064672 ** Tags removed: verification-needed verification-needed-noble ** Tags added: verification-done verification-done-noble -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.ne

[Bug 2064672] Re: [SRU] - fixes for apparmor on noble

2024-07-08 Thread Georgia Garcia
Thanks for the verification, John. I updated the tags based on the results of your tests. ** Tags removed: verification-needed verification-needed-noble ** Tags added: verification-done verification-done-noble -- You received this bug notification because you are a member of Ubuntu Bugs, which i

[Bug 2064672] Re: [SRU] - fixes for apparmor on noble

2024-06-19 Thread Georgia Garcia
Thanks for reviewing, Chris. I have updated the test plan with your suggestions, and I also updated the ppa containing a new version of the package with the wike profile location fixed. I'll also make sure to comment on the bugs in the changelog that verification is not required. ** Description ch

[Bug 2064672] Re: [SRU] - fixes for apparmor on noble

2024-06-19 Thread Georgia Garcia
** Description changed: [ Impact ] This SRU has several fixes: add unconfined profile for tuxedo-control-center (Bug 2046844) fix issues appointed by coverity fix samba profile (https://gitlab.com/apparmor/apparmor/-/issues/386) fix redefinition of _ which caused an issue with tr

[Bug 2032602] Re: [FFe] apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in mantic

2024-06-06 Thread Georgia Garcia
** Tags removed: verification-needed-noble-linux-oracle ** Tags added: verification-done-noble-linux-oracle -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2032602 Title: [FFe] apparmor-4.0.0-alpha2 f

[Bug 2061113] Re: Default included php-fpm profile prevent php-fpm installation

2024-06-06 Thread Georgia Garcia
Fix committed in https://gitlab.com/apparmor/apparmor/-/merge_requests/1251 ** Changed in: apparmor (Ubuntu) Status: New => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2061113

[Bug 2056696] Re: All Snaps are denied the ability to use DBus for notifications and apptray indicators in KDE-based flavors

2024-06-05 Thread Georgia Garcia
** Changed in: apparmor (Ubuntu) Status: Confirmed => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2056696 Title: All Snaps are denied the ability to use DBus for notifications and

[Bug 2057927] Re: lxd vga console throws "Operation not permitted" error

2024-06-05 Thread Georgia Garcia
** Changed in: apparmor (Ubuntu) Status: Confirmed => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2057927 Title: lxd vga console throws "Operation not permitted" error To manage no

[Bug 2065724] Re: After upgrade to Kubuntu 24.04 the Chromium browser freezes when typing to address box

2024-06-05 Thread Georgia Garcia
This is probably happening because before 24.04 plasmashell was not confined, therefore it had the "unconfined" label. But now that it is confined, we need a rule to allow peer_label="plasmashell" ** Also affects: snapd (Ubuntu) Importance: Undecided Status: New -- You received this bu

[Bug 2040250] Re: apparmor notification files verification

2024-06-04 Thread Georgia Garcia
** Tags removed: verification-needed-jammy-linux-nvidia-6.8 verification-needed-noble-linux-gke ** Tags added: verification-done-jammy-linux-nvidia-6.8 verification-done-noble-linux-gke -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2040245] Re: apparmor oops when racing to retrieve a notification

2024-06-04 Thread Georgia Garcia
** Tags removed: verification-needed-jammy-linux-nvidia-6.8 verification-needed-noble-linux-gke ** Tags added: verification-done-jammy-linux-nvidia-6.8 verification-done-noble-linux-gke -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2040192] Re: AppArmor spams kernel log with assert when auditing

2024-06-04 Thread Georgia Garcia
** Tags removed: verification-needed-jammy-linux-nvidia-6.8 verification-needed-noble-linux-gke ** Tags added: verification-done-jammy-linux-nvidia-6.8 verification-done-noble-linux-gke -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2040194] Re: apparmor restricts read access of user namespace mediation sysctls to root

2024-06-04 Thread Georgia Garcia
** Tags removed: verification-needed-jammy-linux-nvidia-6.8 verification-needed-noble-linux-gke ** Tags added: verification-done-jammy-linux-nvidia-6.8 verification-done-noble-linux-gke -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2028253] Re: update apparmor and LSM stacking patch set

2024-06-04 Thread Georgia Garcia
** Tags removed: verification-needed-noble-linux-gke ** Tags added: verification-done-noble-linux-gke ** Tags removed: verification-needed-noble-linux-gcp ** Tags added: verification-done-noble-linux-gcp ** Tags removed: verification-needed-noble-linux-azure ** Tags added: verification-done-noble

[Bug 2028253] Re: update apparmor and LSM stacking patch set

2024-06-04 Thread Georgia Garcia
** Tags removed: verification-needed-noble-linux-lowlatency ** Tags added: verification-done-noble-linux-lowlatency ** Tags removed: verification-needed-noble-linux-ibm ** Tags added: verification-done-noble-linux-ibm -- You received this bug notification because you are a member of Ubuntu Bugs,

[Bug 2032602] Re: [FFe] apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in mantic

2024-06-04 Thread Georgia Garcia
This bug corresponds to the userspace components of AppArmor but it was added in some kernel patches along with Bug 2028253. Verification should be completed in Bug 2028253 ** Tags removed: verification-needed-jammy-linux-aws-6.5 verification-needed-jammy-linux-azure-6.5 verification-needed-jamm

[Bug 2064672] Re: [SRU] - fixes for apparmor on noble

2024-06-04 Thread Georgia Garcia
Hi Simon, The use of --unshare=network does not cause a regression with the bwrap profile. This is the full profile: https://gitlab.com/apparmor/apparmor/-/blob/aa74b9b12d9ed55909489403a0c2514b9ea6a95f/profiles/apparmor/profiles/extras/bwrap-userns-restrict If you look at the bwrap profile itsel

[Bug 2067564] Re: Syslog is flooded with messages when watching videos on Youtube

2024-06-03 Thread Georgia Garcia
** Package changed: apparmor (Ubuntu) => snapd (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2067564 Title: Syslog is flooded with messages when watching videos on Youtube To manage notifi

[Bug 2067443] Re: Several apparmor profiles fail to enable after upgrading to noble

2024-06-03 Thread Georgia Garcia
*** This bug is a duplicate of bug 2064144 *** https://bugs.launchpad.net/bugs/2064144 Hi Mikko. Thanks for the report. This seems to be a duplicate of Bug 2064144, which has the fix on its way to noble. ** This bug has been marked a duplicate of bug 2064144 lxc ships apparmor config that

[Bug 2064672] Re: [SRU] - fixes for apparmor on noble

2024-05-29 Thread Georgia Garcia
** Description changed: [ Impact ] This SRU has several fixes: add unconfined profile for tuxedo-control-center (Bug 2046844) fix issues appointed by coverity fix samba profile (https://gitlab.com/apparmor/apparmor/-/issues/386) fix redefinition of _ which caused an issue with tr

[Bug 2064672] Re: [SRU] - fixes for apparmor on noble

2024-05-27 Thread Georgia Garcia
** Description changed: [ Impact ] This SRU has several fixes: add unconfined profile for tuxedo-control-center (Bug 2046844) fix issues appointed by coverity fix samba profile (https://gitlab.com/apparmor/apparmor/-/issues/386) fix redefinition of _ which caused an issue with tr

[Bug 2047256] Re: Ubuntu 24.04 Some image thumbnails no longer displayed

2024-05-20 Thread Georgia Garcia
Thanks. That version should have the nautilus profile that makes the thumbnails appear, so we will need to dig a bit deeper. Could you paste the results of the following command? This will show us if there is a profile for nautilus loaded and it should look something like this $ sudo aa-status --

[Bug 2064781] Re: setzer does not launch

2024-05-20 Thread Georgia Garcia
*** This bug is a duplicate of bug 2046844 *** https://bugs.launchpad.net/bugs/2046844 Hello! Thanks for tagging apparmor. Yes, this is a duplicate of bug 2046844. We are working on an update that introduces a profile for bwrap which would allow setzer (and several other applications) to work

[Bug 2047256] Re: Ubuntu 24.04 Some image thumbnails no longer displayed

2024-05-17 Thread Georgia Garcia
If you're still running into this issue, do you mind sharing which AppArmor version are you running? For that you can run apt-cache policy apparmor -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/204725

[Bug 2064672] Re: [SRU] - fixes for apparmor on noble

2024-05-07 Thread Georgia Garcia
** Description changed: [ Impact ] This SRU has several fixes: add unconfined profile for tuxedo-control-center (Bug 2046844) fix issues appointed by coverity fix samba profile (https://gitlab.com/apparmor/apparmor/-/issues/386) fix redefinition of _ which caused an issue with tr

[Bug 2062138] Re: test-logprof.py from test_utils_testsuite / test_utils_testsuite3 in ubuntu_qrt_apparmor failing on Azure Standard_A2_v2

2024-05-03 Thread Georgia Garcia
I added the suggested patch to QRT: https://code.launchpad.net/~georgiag/qa-regression-testing/+git/qa-regression-testing/+merge/465526 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2062138 Title: t

[Bug 2064672] Re: [SRU] - fixes for apparmor on noble

2024-05-02 Thread Georgia Garcia
** Description changed: [ Impact ] This SRU has several fixes: add unconfined profile for tuxedo-control-center (Bug 2046844) fix issues appointed by coverity fix samba profile (https://gitlab.com/apparmor/apparmor/-/issues/386) fix redefinition of _ which caused an issue with tr

[Bug 2064672] [NEW] [SRU] - fixes for apparmor on noble

2024-05-02 Thread Georgia Garcia
Public bug reported: [ Impact ] This SRU has several fixes: add unconfined profile for tuxedo-control-center (Bug 2046844) fix issues appointed by coverity fix samba profile (https://gitlab.com/apparmor/apparmor/-/issues/386) fix redefinition of _ which caused an issue with translation, failing

[Bug 2045384] Re: AppArmor patch for mq-posix interface is missing in jammy

2024-03-27 Thread Georgia Garcia
The mqueue patches are present in jammy-linux-gcp-fips: commits 6e7ff802c7b10 and b4ebbcfebd4d3 ** Tags removed: verification-needed-jammy-linux-gcp-fips ** Tags added: verification-done-jammy-linux-gcp-fips -- You received this bug notification because you are a member of Ubuntu Bugs, which is

  1   2   >