Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #860214

Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs

From Christoph Anton Mitterer <calestyo@scientia.net>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs
Date 2017-10-31 17:30 +0100
Message-ID <uGHAm-4mL-5@gated-at.bofh.it> (permalink)
References <uGGkV-3I0-5@gated-at.bofh.it> <uGHgZ-4gA-1@gated-at.bofh.it> <uGGkV-3I0-5@gated-at.bofh.it> <uGHgZ-4gA-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

The severity would have shown people which haven't upgraded, that there
are issues... :-(


On Tue, 2017-10-31 at 16:01 +0000, Ben Hutchings wrote:
> Although you can disable it (security=dac or apparmor=0) if you want.
Sure. I never said this wasn't possible.


> > While I'm usually in favour of anything that improves security
> > (leaving aside the question here whether SELinux wouldn't be the
> > much
> > more powerful solution ;-) )... this happened too silent (e.g. no
> > NEWS entry)... peopl may not even have installed the userland
> > tools.
> 
> The change was noted in the changelog, so it's not silent.

Well one cannot expect the average user to read every single entry of
the kernel changes included in there, can one?


> I intend to add a NEWS entry in the next linux-latest upload.  It
> doesn't make sense to add NEWS to linux-image-* packages as that will
> only be displayed for upgrades that don't involve an ABI bump

Perhaps one should have delayed the activation then until such bump, in
which the user will get an update for the meta-package as well.. which
then contains such notice :-)


> My understanding was that enabling AppArmor shouldn't do very much
> until a policy is loaded (which it won't be if you don't install the
> userland tools).  As you've found, that isn't entirely correct.

Mhh well that was a surprise for me as well :)


> Applications built for Linux are unrelated to Linux?  I don't think
> so.

With that argument, one everything would be related on the kernel...
and on the bootloader (cause without it, not applications at all)...
and so on.

Back to linux.debian.bugs.dist | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs Christoph Anton Mitterer <calestyo@scientia.net> - 2017-10-31 16:10 +0100
  Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs Ben Hutchings <ben@decadent.org.uk> - 2017-10-31 17:10 +0100
    Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs Christoph Anton Mitterer <calestyo@scientia.net> - 2017-10-31 17:30 +0100
      Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs Ben Hutchings <ben@decadent.org.uk> - 2017-10-31 18:30 +0100
        Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs Ben Hutchings <ben@decadent.org.uk> - 2017-11-01 14:50 +0100
    Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs intrigeri <intrigeri@debian.org> - 2017-11-05 12:30 +0100
      Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs Ben Hutchings <ben@decadent.org.uk> - 2017-11-05 14:20 +0100
        Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs intrigeri <intrigeri@debian.org> - 2017-11-05 17:50 +0100

csiph-web