Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #59305

Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs

Path csiph.com!news.mixmin.net!aioe.org!bofh.it!news.nic.it!robomod
From Christoph Anton Mitterer <calestyo@scientia.net>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs
Date Tue, 31 Oct 2017 17:30:02 +0100
Message-ID <uGHAm-4mL-5@gated-at.bofh.it> (permalink)
References <uGGkV-3I0-5@gated-at.bofh.it> <uGHgZ-4gA-1@gated-at.bofh.it> <uGGkV-3I0-5@gated-at.bofh.it> <uGHgZ-4gA-1@gated-at.bofh.it>
X-Original-To Ben Hutchings <ben@decadent.org.uk>, 880441@bugs.debian.org
X-Mailbox-Line From debian-bugs-dist-request@lists.debian.org Tue Oct 31 16:21:13 2017
Old-Return-Path <debbugs@buxtehude.debian.org>
X-Spam-Flag NO
X-Spam-Score -4.209
Reply-To Christoph Anton Mitterer <calestyo@scientia.net>, 880441@bugs.debian.org
Resent-To debian-bugs-dist@lists.debian.org
Resent-Cc Debian Kernel Team <debian-kernel@lists.debian.org>
X-Debian-Pr-Message followup 880441
X-Debian-Pr-Package src:linux
X-Debian-Pr-Source linux
X-Spam-Bayes score:0.0000 Tokens: new, 12; hammy, 150; neutral, 106; spammy, 0. spammytokens: hammytokens:0.000-+--meta-package, 0.000-+--H*RU:sk:calesty, 0.000-+--H*F:U*calestyo, 0.000-+--H*M:scientia, 0.000-+--H*F:D*scientia.net
Content-Type multipart/signed; micalg="sha-512"; protocol="application/x-pkcs7-signature"; boundary="=-Dup+/E4gMXhg0TTsv+Pl"
X-Mailer Evolution 3.26.1-1
MIME-Version 1.0
X-Greylist delayed 441 seconds by postgrey-1.36 at buxtehude; Tue, 31 Oct 2017 16:18:26 UTC
X-Debian-Message from BTS
X-Mailing-List <debian-bugs-dist@lists.debian.org> archive/latest/1415740
List-ID <debian-bugs-dist.lists.debian.org>
List-URL <https://lists.debian.org/debian-bugs-dist/>
Approved robomod@news.nic.it
Lines 162
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Tue, 31 Oct 2017 17:10:56 +0100
X-Original-Message-ID <1509466256.4465.7.camel@scientia.net>
X-Original-References <150946246701.10465.11865358874310555956.reportbug@heisenberg.scientia.net> <1509465684.2748.44.camel@decadent.org.uk> <150946246701.10465.11865358874310555956.reportbug@heisenberg.scientia.net> <1509465684.2748.44.camel@decadent.org.uk>
Xref csiph.com linux.debian.bugs.dist:860214 linux.debian.kernel:59305

Cross-posted to 2 groups.

Show key headers only | View raw


[Multipart message — attachments visible in raw view] - view raw

The severity would have shown people which haven't upgraded, that there
are issues... :-(


On Tue, 2017-10-31 at 16:01 +0000, Ben Hutchings wrote:
> Although you can disable it (security=dac or apparmor=0) if you want.
Sure. I never said this wasn't possible.


> > While I'm usually in favour of anything that improves security
> > (leaving aside the question here whether SELinux wouldn't be the
> > much
> > more powerful solution ;-) )... this happened too silent (e.g. no
> > NEWS entry)... peopl may not even have installed the userland
> > tools.
> 
> The change was noted in the changelog, so it's not silent.

Well one cannot expect the average user to read every single entry of
the kernel changes included in there, can one?


> I intend to add a NEWS entry in the next linux-latest upload.  It
> doesn't make sense to add NEWS to linux-image-* packages as that will
> only be displayed for upgrades that don't involve an ABI bump

Perhaps one should have delayed the activation then until such bump, in
which the user will get an update for the meta-package as well.. which
then contains such notice :-)


> My understanding was that enabling AppArmor shouldn't do very much
> until a policy is loaded (which it won't be if you don't install the
> userland tools).  As you've found, that isn't entirely correct.

Mhh well that was a surprise for me as well :)


> Applications built for Linux are unrelated to Linux?  I don't think
> so.

With that argument, one everything would be related on the kernel...
and on the bootloader (cause without it, not applications at all)...
and so on.

Back to linux.debian.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs Christoph Anton Mitterer <calestyo@scientia.net> - 2017-10-31 16:10 +0100
  Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs Ben Hutchings <ben@decadent.org.uk> - 2017-10-31 17:10 +0100
    Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs Christoph Anton Mitterer <calestyo@scientia.net> - 2017-10-31 17:30 +0100
      Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs Ben Hutchings <ben@decadent.org.uk> - 2017-10-31 18:30 +0100
        Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs Ben Hutchings <ben@decadent.org.uk> - 2017-11-01 14:50 +0100
    Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs intrigeri <intrigeri@debian.org> - 2017-11-05 12:30 +0100
      Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs Ben Hutchings <ben@decadent.org.uk> - 2017-11-05 14:20 +0100
        Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs intrigeri <intrigeri@debian.org> - 2017-11-05 17:50 +0100
  Processed: Re: Bug#880441: linux-image-4.13.0-1-amd64: silently  enabled AppArmor breaks other programs owner@bugs.debian.org (Debian Bug Tracking System) - 2017-10-31 17:10 +0100

csiph-web