Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #227852 > unrolled thread

Stretch => Buster: AppArmor

Started byJesper Dybdal <jd-debian-user@dybdal.dk>
First post2020-10-16 12:30 +0200
Last post2020-10-16 20:20 +0200
Articles 7 — 4 participants

Back to article view | Back to linux.debian.user


Contents

  Stretch => Buster: AppArmor Jesper Dybdal <jd-debian-user@dybdal.dk> - 2020-10-16 12:30 +0200
    Re: Stretch => Buster: AppArmor Reco <recoverym4n@enotuniq.net> - 2020-10-16 12:40 +0200
      Re: Stretch => Buster: AppArmor Tixy <tixy@yxit.co.uk> - 2020-10-16 16:40 +0200
        Re: Stretch => Buster: AppArmor Jesper Dybdal <jd-debian-user@dybdal.dk> - 2020-10-16 17:00 +0200
          Re: Stretch => Buster: AppArmor Tixy <tixy@yxit.co.uk> - 2020-10-16 17:20 +0200
        Re: Stretch => Buster: AppArmor Reco <recoverym4n@enotuniq.net> - 2020-10-16 17:00 +0200
    Re: Stretch => Buster: AppArmor l0f4r0@tuta.io - 2020-10-16 20:20 +0200

#227852 — Stretch => Buster: AppArmor

FromJesper Dybdal <jd-debian-user@dybdal.dk>
Date2020-10-16 12:30 +0200
SubjectStretch => Buster: AppArmor
Message-ID<B0v9L-4bV-5@gated-at.bofh.it>
At some point I will have to upgrade from Stretch to Buster, and I am 
beginning to consider which problems I might run into.  So I have some 
more or less stupid questions that I will post in separate threads - 
this is the first.

Buster enables AppArmor by default.  I know just about nothing at all 
about AppArmor.  Does it constitute a risk that some of my existing 
programs will not work?

For instance, my postfix installation (which is by far the most 
important application I run) uses a few non-standard tcp ports to 
comunicate with helper services and to receive mail submissions - is 
there a risk that AppArmor will block that?

Is there a simple way to disable AppArmor completely until I've had time 
to figure out what to do with it long-term?

Thanks,
Jesper

-- 
Jesper Dybdal
https://www.dybdal.dk

[toc] | [next] | [standalone]


#227855

FromReco <recoverym4n@enotuniq.net>
Date2020-10-16 12:40 +0200
Message-ID<B0vjr-4f4-9@gated-at.bofh.it>
In reply to#227852
	Hi.

On Fri, Oct 16, 2020 at 12:23:30PM +0200, Jesper Dybdal wrote:
> Buster enables AppArmor by default.  I know just about nothing at all
> about AppArmor.  Does it constitute a risk that some of my existing
> programs will not work?

Depends. AppArmor is applied per-binary. If you're using something that
ships an AppArmor policy - it will be enabled.


> For instance, my postfix installation (which is by far the most
> important application I run) uses a few non-standard tcp ports to
> comunicate with helper services and to receive mail submissions - is
> there a risk that AppArmor will block that?

No, because there's no shipped AppArmor policy for postfix in buster.


> Is there a simple way to disable AppArmor completely until I've had
> time to figure out what to do with it long-term?

Adding "apparmor=0" to your kernel cmdline should do the trick.

Reco

[toc] | [prev] | [next] | [standalone]


#227869

FromTixy <tixy@yxit.co.uk>
Date2020-10-16 16:40 +0200
Message-ID<B0z3I-6sr-3@gated-at.bofh.it>
In reply to#227855
On Fri, 2020-10-16 at 13:30 +0300, Reco wrote:
> 
> On Fri, Oct 16, 2020 at 12:23:30PM +0200, Jesper Dybdal wrote:
[...]
> > Is there a simple way to disable AppArmor completely until I've had
> > time to figure out what to do with it long-term?
> 
> Adding "apparmor=0" to your kernel cmdline should do the trick.

Or do what I did, just uninstall the apparmor package which is pulled
in as a 'recommends' of the Linux kernel. Or pin it to priority -1 for
extra paranoia.

-- 
Tixy

[toc] | [prev] | [next] | [standalone]


#227871

FromJesper Dybdal <jd-debian-user@dybdal.dk>
Date2020-10-16 17:00 +0200
Message-ID<B0zn3-6zN-1@gated-at.bofh.it>
In reply to#227869
On 2020-10-16 16:39, Tixy wrote:
> Or do what I did, just uninstall the apparmor package which is pulled
> in as a 'recommends' of the Linux kernel. Or pin it to priority -1 for
> extra paranoia.
>

Thanks.  But will it not be reinstalled the next time there is a kernel 
update?

-- 
Jesper Dybdal
https://www.dybdal.dk

[toc] | [prev] | [next] | [standalone]


#227873

FromTixy <tixy@yxit.co.uk>
Date2020-10-16 17:20 +0200
Message-ID<B0zGq-6VN-15@gated-at.bofh.it>
In reply to#227871
On Fri, 2020-10-16 at 16:59 +0200, Jesper Dybdal wrote:
> On 2020-10-16 16:39, Tixy wrote:
> > Or do what I did, just uninstall the apparmor package which is
> > pulled
> > in as a 'recommends' of the Linux kernel. Or pin it to priority -1
> > for
> > extra paranoia.
> > 
> 
> Thanks.  But will it not be reinstalled the next time there is a kernel 
> update?

Good question, I have apt configured not to install recommends. Makes
me wonder how apparmour got installed in the first place. Maybe it was
there from previous debian versions and the update just enabled it. (I
uninstalled it because after the upgrade to Buster I got loads of
apparmour warnings at boot.)

-- 
Tixy

[toc] | [prev] | [next] | [standalone]


#227872

FromReco <recoverym4n@enotuniq.net>
Date2020-10-16 17:00 +0200
Message-ID<B0zn5-6zN-23@gated-at.bofh.it>
In reply to#227869
	Hi.

On Fri, Oct 16, 2020 at 03:39:29PM +0100, Tixy wrote:
> On Fri, 2020-10-16 at 13:30 +0300, Reco wrote:
> > 
> > On Fri, Oct 16, 2020 at 12:23:30PM +0200, Jesper Dybdal wrote:
> [...]
> > > Is there a simple way to disable AppArmor completely until I've had
> > > time to figure out what to do with it long-term?
> > 
> > Adding "apparmor=0" to your kernel cmdline should do the trick.
> 
> Or do what I did, just uninstall the apparmor package which is pulled
> in as a 'recommends' of the Linux kernel. Or pin it to priority -1 for
> extra paranoia.

That will work too. In buster, apparmor is just another system service
that's started during the boot process. Removing it will remove all both
the security and possible breakage that AppArmor provides.

Reco

[toc] | [prev] | [next] | [standalone]


#227880

Froml0f4r0@tuta.io
Date2020-10-16 20:20 +0200
Message-ID<B0CuB-bw-5@gated-at.bofh.it>
In reply to#227852
Hi,

16 oct. 2020 à 12:23 de jd-debian-user@dybdal.dk:

> Is there a simple way to disable AppArmor completely until I've had time to figure out what to do with it long-term?
>
Considering you are not asking for removal but just deactivation,  the simplest way to me seems to be the following:

sudo systemctl stop apparmor (=> stop the service now)
sudo systemctl disable apparmor (=> prevent the service to be started at next reboot)

Best regards,
l0f4r0

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web