Christian Boltz
07a11c242d
Accepting request 212635 from home:cboltz
...
- add apparmor-profiles-samba-create-dirs.diff to allow samba to
mkdir /var/run/samba and /var/cache/samba (bnc#856651)
- add abstractions/samba to usr.sbin.winbindd profile
- add capabilities ipc_lock and setuid to usr.sbin.winbindd profile (bnc#851131)
- update dovecot profiles to support dovecot 2.x, and add profiles for
the parts of dovecot that were not covered yet (bnc#851984)
NOTE: Please adjust /etc/apparmor.d/tunables/dovecot to your needs.
- %restart_on_update (in parser %postun) is "translated" to stop/start by
the systemd wrapper, which removes AppArmor protection from running
processes. Fixed by using a custom script instead (bnc#853019)
NOTE: The %postun from the previously installed apparmor-parser package
will remove AppArmor protection from running processes a last time.
Run aa-status to get a list of processes you need to restart, or reboot
your computer.
- reload profiles in %post of the apparmor-profiles package
OBS-URL: https://build.opensuse.org/request/show/212635
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=69
2014-01-02 13:01:50 +00:00
Stephan Kulow
9ee417e247
Accepting request 208367 from security:apparmor
...
- add apparmor-abstractions-ssl_certs.diff to allow access to
certificates in /var/lib/ca-certificates/ (bnc#852018) (forwarded request 208366 from cboltz)
OBS-URL: https://build.opensuse.org/request/show/208367
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=60
2013-11-26 13:40:15 +00:00
Christian Boltz
1f745b649e
Accepting request 208366 from home:cboltz
...
- add apparmor-abstractions-ssl_certs.diff to allow access to
certificates in /var/lib/ca-certificates/ (bnc#852018)
OBS-URL: https://build.opensuse.org/request/show/208366
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=67
2013-11-25 23:58:28 +00:00
Stephan Kulow
287fce5cb6
Accepting request 206956 from security:apparmor
...
- add apparmor-profiles-ntpd-r2103.diff with updated driftfile
location for ntpd (bnc#850374) (forwarded request 206954 from cboltz)
OBS-URL: https://build.opensuse.org/request/show/206956
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=59
2013-11-15 12:12:17 +00:00
Christian Boltz
31be6e635f
Accepting request 206954 from home:cboltz
...
- add apparmor-profiles-ntpd-r2103.diff with updated driftfile
location for ntpd (bnc#850374)
OBS-URL: https://build.opensuse.org/request/show/206954
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=65
2013-11-14 20:59:22 +00:00
Stephan Kulow
431fe32aeb
Accepting request 205616 from security:apparmor
...
- apparmor-profiles-samba4.diff, usr.sbin.winbindd: some more profile
updates for samba 4.x and kerberos (bnc#846586#c12 and #c15)
Please include this change in 13.1.
OBS-URL: https://build.opensuse.org/request/show/205616
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=58
2013-11-04 06:04:39 +00:00
Christian Boltz
ca1171db19
Accepting request 205615 from home:cboltz
...
fix wrong bug number in .changes
OBS-URL: https://build.opensuse.org/request/show/205615
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=63
2013-11-02 19:05:50 +00:00
Christian Boltz
58f1803dff
Accepting request 205608 from home:cboltz
...
- apparmor-profiles-samba4.diff, usr.sbin.winbindd: some more profile
updates for samba 4.x and kerberos (bnc#846054#c12 and #c15)
Please include this change in 13.1.
OBS-URL: https://build.opensuse.org/request/show/205608
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=62
2013-11-02 16:11:42 +00:00
Stephan Kulow
7e87bea71b
Accepting request 205295 from security:apparmor
...
- add apparmor-profiles-dnsmasq.diff - add missing permissions for
libvirt-generated files to dnsmasq profile (bnc#848215)
Please also forward this to 13.1
OBS-URL: https://build.opensuse.org/request/show/205295
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=57
2013-10-31 14:38:12 +00:00
Christian Boltz
af1a622b04
replace apparmor-profiles-dnsmasq.diff with upstreamed patch
...
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=60
2013-10-30 20:47:57 +00:00
Christian Boltz
d171a3c620
- add apparmor-profiles-dnsmasq.diff - add missing permissions for
...
libvirt-generated files to dnsmasq profile (bnc#848215)
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=59
2013-10-30 11:36:14 +00:00
Tomáš Chvátal
1ee3b5a2e5
Accepting request 204033 from security:apparmor
...
- apparmor-profiles-samba4.diff, usr.sbin.winbindd: some more profile
updates for samba 4.x (bnc#846054#c5)
Please also include this change in 13.1
OBS-URL: https://build.opensuse.org/request/show/204033
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=56
2013-10-21 10:28:31 +00:00
Christian Boltz
70d6af76c0
Accepting request 204031 from home:cboltz
...
whitespace fix in patch
OBS-URL: https://build.opensuse.org/request/show/204031
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=57
2013-10-20 14:39:56 +00:00
Christian Boltz
dfbaa33afd
Accepting request 204015 from home:cboltz
...
- apparmor-profiles-samba4.diff, usr.sbin.winbindd: some more profile
updates for samba 4.x (bnc#846054#c5)
Please also include this change in 13.1
OBS-URL: https://build.opensuse.org/request/show/204015
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=56
2013-10-20 12:05:07 +00:00
Tomáš Chvátal
7a538f7721
Accepting request 203528 from security:apparmor
...
- add apparmor-profiles-samba4.diff - various profile additions for
samba 4.x (bnc#845867, bnc#846054)
- update usr.sbin.winbindd for samba 4.x (bnc#845867, bnc#846054)
Please also include this in 13.1 - without it, it's impossible to start samba.
OBS-URL: https://build.opensuse.org/request/show/203528
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=55
2013-10-17 11:58:19 +00:00
Christian Boltz
9e1473f092
Accepting request 203441 from home:cboltz
...
smbd profile:
+ /{,var/}run/samba/ncalrpc/** rw,
OBS-URL: https://build.opensuse.org/request/show/203441
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=54
2013-10-15 22:16:03 +00:00
Christian Boltz
a4facc5105
Accepting request 203431 from home:cboltz
...
- add apparmor-profiles-samba4.diff - various profile additions for
samba 4.x (bnc#845867, bnc#846054)
- update usr.sbin.winbindd for samba 4.x (bnc#845867, bnc#846054)
OBS-URL: https://build.opensuse.org/request/show/203431
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=53
2013-10-15 21:44:56 +00:00
Stephan Kulow
a4cced906b
Accepting request 201623 from security:apparmor
...
- update apparmor-init.py-gsoc.diff to the final GSoC apparmor/__init__.py
Please also include this change in 13.1
OBS-URL: https://build.opensuse.org/request/show/201623
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=54
2013-10-02 11:26:56 +00:00
Christian Boltz
359d038285
Accepting request 201622 from home:cboltz
...
- update apparmor-init.py-gsoc.diff to the final GSoC apparmor/__init__.py
OBS-URL: https://build.opensuse.org/request/show/201622
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=51
2013-10-01 15:59:24 +00:00
Stephan Kulow
ee7a886060
Accepting request 199887 from security:apparmor
...
- add apparmor-fix-url-in-manpages-r2093.diff: fix URL in manpages
- add apparmor-unconfined-lang-r2094.diff: fix aa-unconfined to work
in all languages
Please also forward those fixes to 13.1 (forwarded request 199886 from cboltz)
OBS-URL: https://build.opensuse.org/request/show/199887
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=53
2013-09-23 09:42:47 +00:00
Christian Boltz
568a5c7083
Accepting request 199886 from home:cboltz
...
- add apparmor-fix-url-in-manpages-r2093.diff: fix URL in manpages
- add apparmor-unconfined-lang-r2094.diff: fix aa-unconfined to work
in all languages
Please also forward those fixes to 13.1
OBS-URL: https://build.opensuse.org/request/show/199886
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=49
2013-09-20 20:54:16 +00:00
Stephan Kulow
7ba2c9b004
Accepting request 199336 from security:apparmor
...
- fix ntp by allowing read access to openssl.cnf
- add apparmor-utils-po-de-r2091.diff: fix some (mis)translations
OBS-URL: https://build.opensuse.org/request/show/199336
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=51
2013-09-17 13:01:33 +00:00
Christian Boltz
7800cf233b
Accepting request 199335 from home:cboltz
...
- add apparmor-utils-po-de-r2091.diff: fix some (mis)translations
OBS-URL: https://build.opensuse.org/request/show/199335
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=47
2013-09-16 22:11:37 +00:00
Christian Boltz
3350370468
Accepting request 199292 from home:seife:branches:security:apparmor
...
fix ntp by allowing read access to openssl.cnf (see comment in patch)
OBS-URL: https://build.opensuse.org/request/show/199292
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=46
2013-09-16 20:26:54 +00:00
Tomáš Chvátal
a20d3d84a3
Accepting request 198936 from security:apparmor
...
- add apparmor-abstractions-r2089-r2090.diff (from upstream 2.8 branch)
- p11-kit needs access to /usr/share/p11-kit/modules
- allow reading /etc/machine-id in the dbus-session abstraction
- add apparmor-init.py-gsoc.diff - make apparmor/__init__.py ready for
the new tools developed in GSoC (forwarded request 198933 from cboltz)
OBS-URL: https://build.opensuse.org/request/show/198936
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=50
2013-09-13 12:50:59 +00:00
Christian Boltz
b950fbc28a
Accepting request 198933 from home:cboltz
...
- add apparmor-abstractions-r2089-r2090.diff (from upstream 2.8 branch)
- p11-kit needs access to /usr/share/p11-kit/modules
- allow reading /etc/machine-id in the dbus-session abstraction
- add apparmor-init.py-gsoc.diff - make apparmor/__init__.py ready for
the new tools developed in GSoC
OBS-URL: https://build.opensuse.org/request/show/198933
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=44
2013-09-13 11:53:29 +00:00
Stephan Kulow
05d7ae7978
Accepting request 196153 from security:apparmor
...
- add apparmor-no-perl-smartmatch-r2088.diff: ~~ was marked as experimental
in perl 5.18 again - use grep instead (upstream 2.8 branch r2088)
- fix ruby requires (forwarded request 196152 from cboltz)
OBS-URL: https://build.opensuse.org/request/show/196153
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=49
2013-08-27 18:32:38 +00:00
Christian Boltz
cdba64057c
Accepting request 196152 from home:cboltz
...
- add apparmor-no-perl-smartmatch-r2088.diff: ~~ was marked as experimental
in perl 5.18 again - use grep instead (upstream 2.8 branch r2088)
- fix ruby requires
OBS-URL: https://build.opensuse.org/request/show/196152
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=42
2013-08-23 22:02:24 +00:00
Christian Boltz
644c700c5c
Accepting request 195617 from home:cboltz
...
- update to AppArmor 2.8.2
- several fixes for python3 compability
- various profile improvements:
- various additions to abstractions/fonts
- move poppler's cMaps from gnome to fonts; gnome includes fonts
- deny @{HOME}/.gnome2/keyrings/** to abstractions/private-files-strict
- add read access to @{PROC}/sys/vm/overcommit_memory to abstractions/base
(bnc#824577)
- update pulseaudio directory and cookie file paths
- add missing permissions to the nscd profile (bnc#807104)
- deny capability block_suspend to nscd (bnc#807104)
- MariaDB compatability in abstractions/mysql (bnc#798183)
- see http://wiki.apparmor.net/index.php/ReleaseNotes_2_8_2 for all details
- removed upstream(ed) patches
- apparmor-abstractions-mysql-path.diff
- apparmor-profiles-nscd.diff
- apparmor-python3-r2052.diff
- swig for python3 is broken on openSUSE 12.2 - build python-apparmor
(for python2) instead on 12.2
OBS-URL: https://build.opensuse.org/request/show/195617
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=41
2013-08-19 16:02:10 +00:00
Christian Boltz
4da2ecce1b
Accepting request 188225 from home:cboltz
...
- add python3-apparmor subpackage (currently py2 OR py3 package can be
build, but not both at the same time)
- add upstream apparmor-python3-r2052.diff to fix various python3 issues
- Ruby 2.0 mkmf gets the path to ruby.h wrong (bnc#822277)
- enable python and ruby subpackages (using %bcond_without)
- update/fix paths in %files for python and ruby subpackages
OBS-URL: https://build.opensuse.org/request/show/188225
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=40
2013-08-15 12:10:13 +00:00
Stephan Kulow
235b922f0e
Accepting request 175481 from security:apparmor
...
- do not package directories as %config - especially not as noreplace
- add Requires: insserv to parser package (needed by initscript)
OBS-URL: https://build.opensuse.org/request/show/175481
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=48
2013-05-16 07:34:36 +00:00
Christian Boltz
77f186fe2c
package /etc/apparmor.d/disable again (was lost in Coolo's SR)
...
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=38
2013-05-13 23:04:07 +00:00
Christian Boltz
2ea42efed0
Accepting request 175273 from home:coolo:branches:openSUSE:Factory
...
- do not package directories as %config - especially not as noreplace
OBS-URL: https://build.opensuse.org/request/show/175273
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=37
2013-05-13 23:00:39 +00:00
Christian Boltz
a516810243
Accepting request 162270 from home:cboltz
...
- add Requires: insserv to parser package (needed by initscript)
OBS-URL: https://build.opensuse.org/request/show/162270
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=36
2013-04-02 20:03:24 +00:00
Stephan Kulow
3b154491eb
Accepting request 157433 from security:apparmor
...
This time with better paperwork ;-)
- nscd profile: add missing permissions and deny capability block_suspend
(bnc#807104, apparmor-profiles-nscd.diff)
Please also add this patch to openSUSE 12.3
The patch only adds permissions, which means it can't break anything.
Even "deny capability block_suspend" doesn't take away any permissions
(everything that is not allowed is denied by default). The deny rule
just disables the logging for capability block_suspend. (forwarded request 157429 from cboltz)
OBS-URL: https://build.opensuse.org/request/show/157433
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=47
2013-03-08 08:07:27 +00:00
Christian Boltz
27e7628744
Accepting request 157429 from home:cboltz
...
This time with better paperwork ;-)
- nscd profile: add missing permissions and deny capability block_suspend
(bnc#807104, apparmor-profiles-nscd.diff)
Please also add this patch to openSUSE 12.3
The patch only adds permissions, which means it can't break anything.
Even "deny capability block_suspend" doesn't take away any permissions
(everything that is not allowed is denied by default). The deny rule
just disables the logging for capability block_suspend.
OBS-URL: https://build.opensuse.org/request/show/157429
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=34
2013-03-05 21:19:30 +00:00
Christian Boltz
fb230fe709
Accepting request 157409 from home:cboltz
...
- nscd profile: add missing permissions and deny capability block_suspend
(bnc#807104)
Please also add this patch to openSUSE 12.3
The patch only adds permissions, which means it can't break anything.
Even "deny capability block_suspend" doesn't take away any permissions
(everything that is not allowed is denied by default). The deny rule
just disables the logging for capability block_suspend.
OBS-URL: https://build.opensuse.org/request/show/157409
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=33
2013-03-05 18:19:50 +00:00
Stephan Kulow
cc224e3cab
Accepting request 155663 from security:apparmor
...
- Add missing files to SRPM (bnc#777471) (forwarded request 155632 from jengelh)
OBS-URL: https://build.opensuse.org/request/show/155663
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=46
2013-02-18 12:45:23 +00:00
Christian Boltz
5c998ab082
Accepting request 155632 from home:jengelh:branches:security:apparmor
...
- Add missing files to SRPM (bnc#777471)
OBS-URL: https://build.opensuse.org/request/show/155632
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=31
2013-02-17 15:48:15 +00:00
Stephan Kulow
7615c23448
Accepting request 148268 from security:apparmor
...
- update abstractions/mysql with correct paths and add MariaDB paths
(bnc#798183) (forwarded request 148267 from cboltz)
OBS-URL: https://build.opensuse.org/request/show/148268
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=44
2013-01-14 08:35:25 +00:00
Christian Boltz
a8c35deb1a
Accepting request 148267 from home:cboltz
...
- update abstractions/mysql with correct paths and add MariaDB paths
(bnc#798183)
OBS-URL: https://build.opensuse.org/request/show/148267
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=29
2013-01-13 14:11:59 +00:00
Stephan Kulow
2e6ea73466
Accepting request 147966 from security:apparmor
...
- update to AppArmor 2.8.1 (=2.8 branch r2069)
Bugfix release, http://wiki.apparmor.net/index.php/ReleaseNotes_2_8_1
Most important changes are:
- add various missing parts to profiles and abstractions
- fix a possible x conflict with hats or child profiles in
apparmor_parser
- fix and speedup stdin handling in aa-decode
- various other bugfixes
- add pkgconfig support to libapparmor
- remove upstream(ed) patches (forwarded request 147965 from cboltz)
OBS-URL: https://build.opensuse.org/request/show/147966
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=43
2013-01-11 08:23:51 +00:00
Christian Boltz
c33e50b1a0
Accepting request 147965 from home:cboltz
...
- update to AppArmor 2.8.1 (=2.8 branch r2069)
Bugfix release, http://wiki.apparmor.net/index.php/ReleaseNotes_2_8_1
Most important changes are:
- add various missing parts to profiles and abstractions
- fix a possible x conflict with hats or child profiles in
apparmor_parser
- fix and speedup stdin handling in aa-decode
- various other bugfixes
- add pkgconfig support to libapparmor
- remove upstream(ed) patches
OBS-URL: https://build.opensuse.org/request/show/147965
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=27
2013-01-10 19:32:25 +00:00
Ismail Dönmez
58b9c04317
Accepting request 144622 from security:apparmor
...
- verify tarball with gpg-offline (forwarded request 144621 from cboltz)
OBS-URL: https://build.opensuse.org/request/show/144622
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=42
2012-12-09 13:08:49 +00:00
Christian Boltz
76780104ab
Accepting request 144621 from home:cboltz
...
- verify tarball with gpg-offline
OBS-URL: https://build.opensuse.org/request/show/144621
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=25
2012-12-07 16:18:41 +00:00
Stephan Kulow
484af9f671
Accepting request 136134 from security:apparmor
...
- fix directory flags for /etc/apparmor.d to be in sync between
-parser and -profiles subpackage
- remove %stop_on_removal for no longer existing aaeventd (bnc#781564)
- don't hide TeX output when building the parser and techdoc
OBS-URL: https://build.opensuse.org/request/show/136134
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=41
2012-09-27 11:36:12 +00:00
Christian Boltz
1b9e252479
Accepting request 135892 from home:coolo:branches:openSUSE:Factory
...
- fix directory flags for /etc/apparmor.d to be in sync between
-parser and -profiles subpackage
OBS-URL: https://build.opensuse.org/request/show/135892
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=23
2012-09-26 20:23:10 +00:00
Christian Boltz
323716627e
Accepting request 135294 from home:cboltz
...
- remove %stop_on_removal for no longer existing aaeventd (bnc#781564)
- don't hide TeX output when building the parser and techdoc
OBS-URL: https://build.opensuse.org/request/show/135294
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=22
2012-09-21 20:10:44 +00:00
Ismail Dönmez
a31506b743
Accepting request 130598 from security:apparmor
...
- clear and update inconsistent profile cache (bnc#774529)
- fix wording in two older .changes entries (usrMove -> usrMerge)
OBS-URL: https://build.opensuse.org/request/show/130598
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=40
2012-08-10 17:00:34 +00:00
Christian Boltz
af841ad5b9
Accepting request 130597 from home:cboltz
...
- clear and update inconsistent profile cache (bnc#774529)
- fix wording in two older .changes entries (usrMove -> usrMerge)
OBS-URL: https://build.opensuse.org/request/show/130597
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=20
2012-08-10 10:37:26 +00:00