Discussion:
Bug#925130: release-notes: [buster] AppArmor section is misleading as most profiles are not enforced
(too old to reply)
Mathieu Parent
2019-03-20 06:40:02 UTC
Permalink
Package: release-notes
Severity: normal
X-Debbugs-Cc: Debian AppArmor Team <pkg-apparmor-***@lists.alioth.debian.org>

Dear Maintainer,

Section 2.2.2 says "Debian buster has AppArmor enabled per default", which
is right. But most profiles are in complain mode.

Maybe something should be written about it?

Regards

Mathieu Parent
intrigeri
2019-03-20 07:50:02 UTC
Permalink
Control: tag -1 + moreinfo

Hi Mathieu,

thanks for caring.

Disclaimer: I didn't read the release notes bits Jonas wrote yet.
Post by Mathieu Parent
But most profiles are in complain mode.
"most" of which set of profiles?

FTR, in a sid GNOME desktop VM with a few extra packages on top, that
ship AppArmor profiles (LXC, haveged, libvirt, snapd, tor,
Thunderbird, torbrowser-launcher), I see:

- 31 profiles in enforce mode
- 9 profiles in complain mode

It seems to me that most packages that ship AppArmor policy
set it to enforce mode. There are a few exceptions, e.g.:

- apparmor-profiles: the label on the box explains why and should
hopefully discourage the vast majority of users to install it)
- Thunderbird
- some of the LibreOffice profiles

Thanks again!

Cheers,
--
intrigeri
Debian Bug Tracking System
2019-03-20 07:50:02 UTC
Permalink
Post by intrigeri
tag -1 + moreinfo
Bug #925130 [release-notes] release-notes: [buster] AppArmor section is misleading as most profiles are not enforced
Added tag(s) moreinfo.
--
925130: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=925130
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Debian Bug Tracking System
2019-03-20 21:10:01 UTC
Permalink
Your message dated Wed, 20 Mar 2019 21:59:37 +0100
with message-id <***@mail.gmail.com>
and subject line Re: [pkg-apparmor] Bug#925130: release-notes: [buster] AppArmor section is misleading as most profiles are not enforced
has caused the Debian Bug report #925130,
regarding release-notes: [buster] AppArmor section is misleading as most profiles are not enforced
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ***@bugs.debian.org
immediately.)
--
925130: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=925130
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
intrigeri
2019-03-21 06:50:01 UTC
Permalink
I spoke too fast. On my machine, in
/sys/kernel/security/apparmor/profiles, I have 32 enforce lines and 23
complain lines. This is certainly not "most". And I have
apparmor-profiles installed.
[...]
I'm closing this report.
Thanks for taking a closer look :)
I'm too late on this for buster, but I think the smbd and nmbd
profiles can be enabled by default in bullseye.
Great! Feel free to file a bug about it, ideally with a testing
report.

Cheers,
--
intrigeri
Loading...