Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #59474

Re: recommends for apparmor in newest linux-image-4.13

From Ben Hutchings <ben@decadent.org.uk>
Newsgroups linux.debian.kernel, linux.debian.devel
Subject Re: recommends for apparmor in newest linux-image-4.13
Date 2017-11-23 15:10 +0100
Message-ID <uP0mt-6pO-1@gated-at.bofh.it> (permalink)
References <uP037-64b-1@gated-at.bofh.it> <uP0cO-67h-11@gated-at.bofh.it> <uP0mt-6pO-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Thu, 2017-11-23 at 14:58 +0100, Christoph Hellwig wrote:
> On Thu, Nov 23, 2017 at 01:55:49PM +0000, Ben Hutchings wrote:
> > AppArmor is the default LSM.
> 
> There is no such thing as a default LSM in Linux.

$ grep DEFAULT_SECURITY /boot/config-4.13.0-1-amd64 
# CONFIG_DEFAULT_SECURITY_SELINUX is not set
# CONFIG_DEFAULT_SECURITY_TOMOYO is not set
CONFIG_DEFAULT_SECURITY_APPARMOR=y
# CONFIG_DEFAULT_SECURITY_DAC is not set
CONFIG_DEFAULT_SECURITY="apparmor"

> > > The changelog suggests it was done that systemd units might use it,
> > > but in that case those systemd units should depend on apparmor.
> > 
> > They don't depend on AppArmor unless it's enabled.  Which is a decision
> > made in the kernel configuration (potentially overriden by the kernel
> > comamnd line).
> 
> So we should not need the recommends.
-- 
Ben Hutchings
When in doubt, use brute force. - Ken Thompson

Back to linux.debian.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

recommends for apparmor in newest linux-image-4.13 Christoph Hellwig <hch@lst.de> - 2017-11-23 14:50 +0100
  Re: recommends for apparmor in newest linux-image-4.13 Ben Hutchings <ben@decadent.org.uk> - 2017-11-23 15:00 +0100
    Re: recommends for apparmor in newest linux-image-4.13 Ben Hutchings <ben@decadent.org.uk> - 2017-11-23 15:10 +0100
      Re: recommends for apparmor in newest linux-image-4.13 Christoph Hellwig <hch@lst.de> - 2017-11-23 15:20 +0100
        Re: recommends for apparmor in newest linux-image-4.13 Lars Wirzenius <liw@liw.fi> - 2017-11-23 16:10 +0100
          Re: recommends for apparmor in newest linux-image-4.13 Christoph Hellwig <hch@lst.de> - 2017-11-28 20:20 +0100
            Re: recommends for apparmor in newest linux-image-4.13 md@Linux.IT (Marco d'Itri) - 2017-11-29 00:50 +0100
              Re: recommends for apparmor in newest linux-image-4.13 Michael Stone <mstone@debian.org> - 2017-11-29 04:20 +0100
    Re: recommends for apparmor in newest linux-image-4.13 Christoph Hellwig <hch@lst.de> - 2017-11-23 15:20 +0100
  Re: recommends for apparmor in newest linux-image-4.13 Wouter Verhelst <wouter@debian.org> - 2017-11-23 15:10 +0100
    Re: recommends for apparmor in newest linux-image-4.13 maximilian attems <maks@stro.at> - 2017-11-23 16:40 +0100
      Re: recommends for apparmor in newest linux-image-4.13 Ian Jackson <ijackson@chiark.greenend.org.uk> - 2017-11-23 18:30 +0100

csiph-web