Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #861055

Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs

From Ben Hutchings <ben@decadent.org.uk>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs
Date 2017-11-05 14:20 +0100
Message-ID <uIt0d-5B5-5@gated-at.bofh.it> (permalink)
References (1 earlier) <uGGkV-3I0-5@gated-at.bofh.it> <uGHgZ-4gA-1@gated-at.bofh.it> <uIrhL-4sD-1@gated-at.bofh.it> <uGGkV-3I0-5@gated-at.bofh.it> <uIrhL-4sD-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Sun, 2017-11-05 at 12:21 +0100, intrigeri wrote:
> Hi,
> 
> Ben Hutchings:
> > My understanding was that enabling AppArmor shouldn't do very much
> > until a policy is loaded (which it won't be if you don't install the
> > userland tools).  As you've found, that isn't entirely correct.
> 
> Let me clear a potential misunderstanding:
> 
>  - It *is* correct that the AppArmor LSM doesn't do very much if no
>    policy is loaded, i.e. if the apparmor package is not installed.
> 
>  - The only report I've heard of so far of breakage caused by AppArmor
>    being enabled in the kernel by default, on systems that have no
>    AppArmor policy loaded, is #880490. That bug was not about AppArmor
>    denying anything, but about systemd trying to switch to an AppArmor
>    profile that was not loaded (precisely because the apparmor package
>    was not installed). Thankfully that bug has been fixed very
>    quickly. According to codesearch.debian.net it was the only
>    instance of this problem. I'm sorry I didn't think of this corner
>    case initially.
> 
> > Still, I'll bump this back to serious as I don't think we should let
> > this into testing yet.
> 
> I think this does not apply anymore, now that the "unrelated" breakage
> has been fixed, and the reasons behind it clarified. What do
> you think?

Yes, I now understand this.  I'll add a Recommends: apparmor for the
next upload so this broken configuration is less likely to occur.

The current unstable version FTBFS on several architectures, so it
wouldn't have gone into testing anyway.

Ben.

-- 
Ben Hutchings
Never put off till tomorrow what you can avoid all together.

Back to linux.debian.bugs.dist | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs Christoph Anton Mitterer <calestyo@scientia.net> - 2017-10-31 16:10 +0100
  Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs Ben Hutchings <ben@decadent.org.uk> - 2017-10-31 17:10 +0100
    Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs Christoph Anton Mitterer <calestyo@scientia.net> - 2017-10-31 17:30 +0100
      Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs Ben Hutchings <ben@decadent.org.uk> - 2017-10-31 18:30 +0100
        Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs Ben Hutchings <ben@decadent.org.uk> - 2017-11-01 14:50 +0100
    Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs intrigeri <intrigeri@debian.org> - 2017-11-05 12:30 +0100
      Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs Ben Hutchings <ben@decadent.org.uk> - 2017-11-05 14:20 +0100
        Bug#880441: linux-image-4.13.0-1-amd64: silently enabled AppArmor breaks other programs intrigeri <intrigeri@debian.org> - 2017-11-05 17:50 +0100

csiph-web