Commit Graph

34 Commits

Author SHA256 Message Date
Christian Boltz
fb230fe709 Accepting request 157409 from home:cboltz
- nscd profile: add missing permissions and deny capability block_suspend
  (bnc#807104)

Please also add this patch to openSUSE 12.3

The patch only adds permissions, which means it can't break anything.
Even "deny capability block_suspend" doesn't take away any permissions 
(everything that is not allowed is denied by default). The deny rule
just disables the logging for capability block_suspend.

OBS-URL: https://build.opensuse.org/request/show/157409
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=33
2013-03-05 18:19:50 +00:00
Christian Boltz
5c998ab082 Accepting request 155632 from home:jengelh:branches:security:apparmor
- Add missing files to SRPM (bnc#777471)

OBS-URL: https://build.opensuse.org/request/show/155632
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=31
2013-02-17 15:48:15 +00:00
Christian Boltz
a8c35deb1a Accepting request 148267 from home:cboltz
- update abstractions/mysql with correct paths and add MariaDB paths
  (bnc#798183)

OBS-URL: https://build.opensuse.org/request/show/148267
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=29
2013-01-13 14:11:59 +00:00
Christian Boltz
c33e50b1a0 Accepting request 147965 from home:cboltz
- update to AppArmor 2.8.1 (=2.8 branch r2069)
  Bugfix release, http://wiki.apparmor.net/index.php/ReleaseNotes_2_8_1
  Most important changes are:
  - add various missing parts to profiles and abstractions
  - fix a possible x conflict with hats or child profiles in 
    apparmor_parser
  - fix and speedup stdin handling in aa-decode
  - various other bugfixes
  - add pkgconfig support to libapparmor
- remove upstream(ed) patches

OBS-URL: https://build.opensuse.org/request/show/147965
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=27
2013-01-10 19:32:25 +00:00
Christian Boltz
76780104ab Accepting request 144621 from home:cboltz
- verify tarball with gpg-offline

OBS-URL: https://build.opensuse.org/request/show/144621
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=25
2012-12-07 16:18:41 +00:00
Christian Boltz
1b9e252479 Accepting request 135892 from home:coolo:branches:openSUSE:Factory
- fix directory flags for /etc/apparmor.d to be in sync between
  -parser and -profiles subpackage

OBS-URL: https://build.opensuse.org/request/show/135892
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=23
2012-09-26 20:23:10 +00:00
Christian Boltz
323716627e Accepting request 135294 from home:cboltz
- remove %stop_on_removal for no longer existing aaeventd (bnc#781564)
- don't hide TeX output when building the parser and techdoc

OBS-URL: https://build.opensuse.org/request/show/135294
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=22
2012-09-21 20:10:44 +00:00
Christian Boltz
af841ad5b9 Accepting request 130597 from home:cboltz
- clear and update inconsistent profile cache (bnc#774529)
- fix wording in two older .changes entries (usrMove -> usrMerge)

OBS-URL: https://build.opensuse.org/request/show/130597
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=20
2012-08-10 10:37:26 +00:00
Christian Boltz
6fcab6dcf9 Accepting request 130008 from home:cboltz
- abstractions/bash: update /bin/ls to also match /usr/bin/ls (usrMove)

OBS-URL: https://build.opensuse.org/request/show/130008
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=18
2012-08-05 16:14:12 +00:00
Christian Boltz
de0f7c1685 Accepting request 129259 from home:WernerFink:branches:security:apparmor
- Add required fonts for new TeXLive 2012

OBS-URL: https://build.opensuse.org/request/show/129259
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=16
2012-07-30 10:20:33 +00:00
Christian Boltz
b13b1cb7a0 Accepting request 127334 from home:cboltz
- update /bin/ping profile to also match /usr/bin/ping (usrMove)

OBS-URL: https://build.opensuse.org/request/show/127334
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=14
2012-07-06 22:51:54 +00:00
Christian Boltz
142cd0f4ac Accepting request 123313 from home:cboltz
- update to AppArmor 2.8.0 (= r2047)
  - new utility aa-easyprof - templated profile generation tool (the resulting
    profile may be less strict than profiles generated with genprof/logprof)
  - various small bugfixes
- removed upstreamed patches

OBS-URL: https://build.opensuse.org/request/show/123313
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=12
2012-06-02 21:50:07 +00:00
Christian Boltz
0237c25017 Accepting request 116784 from home:cboltz
- add apparmor-techdoc.patch to remove traces of the build time in PDF files

- update to AppArmor 2.8 beta5 (= 2.7.103 / r2031)
  - new utility aa-exec to confine a program with the specified AppArmor profile
  - add support for mount rules
  - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_8 for full upstream
    changelog
- removed upstreamed and backported patches
- remove outdated autobuild and "disable repo" patches that were disabled since
  the AppArmor 2.7 package
- create the Immunix::SubDomain compat perl module only for openSUSE <= 12.1
  (bnc#720617 #c7)

OBS-URL: https://build.opensuse.org/request/show/116784
OBS-URL: https://build.opensuse.org/package/show/security:apparmor/apparmor?expand=0&rev=10
2012-05-08 20:39:34 +00:00
Stephan Kulow
2550ecdff9 Accepting request 113963 from security:apparmor
- replace patch for dnsmasq profile with upstream patch (bnc#738905)

- add apparmor-r2022-log-parser-network-bnc755923.patch - logprof didn't
  create network rules because of changed log format (bnc#755923, lp#800826)
- add profile for samba winbindd (bnc#748499)

- fix dnsmasq profile (bnc#738905)

- add 0001-fix-for-lp929531.patch to allow reading 
  /sys/devices/system/cpu/online in abstractions/base (lp#929531)

OBS-URL: https://build.opensuse.org/request/show/113963
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=33
2012-04-17 05:43:31 +00:00
Stephan Kulow
c958d9cad3 Accepting request 102458 from security:apparmor:factory
- Update to AppArmor 2.7.2 (= 2.7 branch / r1894)
  - move various permissions from httpd2-prefork profile to
    abstractions/apache2-common. Backward-incompatible change: *.htaccess
    files are no longer allowed for ^HANDLING_UNTRUSTED_INPUT
  - allow access for more /usr/lib*/samba/ files for smbd (bnc#725967#c5)
  - allow various .conf files for dovecot (lp#458922)
  - disallow wl for *.so in @{HOME}/.pki/nssdb/ in abstractions/private-files
    and abstractions/private-files-strict (lp#911847)
  - update abstractions/kde, private-files* and ubuntu-browsers.d/user-files
    to use ~/.kde4, not only ~/.kde (bnc#741592)
  - block write access to ~/.kde{,4}/env in abstractions/private-files
    (lp#914190)
  - allow write access for personal dictionary etc. in abstractions/aspell
    (lp#917859)
  - when using genprof for a script, include read access to the script itsself
  - automatically include abstractions/python or abstractions/ruby for
    python/ruby scripts
  - add profile for smbldap-useradd and allow smbd to call it (bnc#738041)
  - allow creation of the .config directory in abstractions/enchant (lp#914184)
  - allow TFTP read-only access in dnsmasq profile (lp#905412)
  - allow capability dac_read_search for syslog-ng (bnc#731876)
  - add p11-kit abstraction and include it in abstractions/authentification
    (lp#912754, lp#912752)
  - add audacity to abstractions/ubuntu-media-players (lp#899963)
  - allow software-center, fireclam plugin, [tT]unar, exo-open, kate and
    /dev/nvidia* in abstractons/ubuntu-browsers.d/* (lp#662906, lp#562831,
    lp#890894, lp#890894, lp#884748)
  - fix typo for multiarch gconf-modules in abstractions/base (lp#904548)
  - allow avahi to do dbus introspection (lp#769148)
  - allow access to ~/.fonts.conf.d in abstractions/fonts (lp#870992)
  - allow transmission in abstractions/ubuntu-bittorrent-clients (lp#852062)
  - allow reading ~/.cups/client.conf and ~/.cups/lpoptions in
    abstractions/cups-client (lp#887992)
  - allow read access of /etc/python{2,3}.[0-7]*/sitecustomize.py in
    abstractions/python (lp#860856)
  - various updates to the sshd profile (lp#817956)
  - (and some more changes I already included in the apparmor-2.7-branch.diff)

OBS-URL: https://build.opensuse.org/request/show/102458
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=32
2012-02-02 16:56:20 +00:00
Stephan Kulow
b2f1c70e39 Accepting request 98697 from security:apparmor:factory
- Update to AppArmor 2.7.0 (= r1858)
  - make traceroute6 work (bnc#733312)
  - allow access to pyconfig.h in abstractions/python (lp#840734)
  - fix logprof/genprof for hex-encoded program filenames (= filenames
    containing space etc.)
- add apparmor-2.7-branch.diff with some upstreamed fixes:
  - usr.sbin.smbd needs read access for /etc/netgroup (bnc#738041)
  - create /etc/apparmor.d/tunables/multiarch.d as directory, not as file
  - fix syntax error in abstractons/python

- changed a $ -> % (typo)

OBS-URL: https://build.opensuse.org/request/show/98697
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=31
2012-01-05 12:51:05 +00:00
Stephan Kulow
76a45f653d Accepting request 93892 from security:apparmor:factory
- package subdomain.conf only in -parser, not in -utils package
- package libapparmor.so and libimmunix.so only in libapparmor-devel,
  not in libapparmor1
- make Provides for perl-libapparmor versioned to avoid self-Obsoletes
- move libapparmor.a and libimmunix.a from libapparmor1 to 
  libapparmor-devel package

- update to AppArmor 2.7.0 rc2
  Most of the changes since rc1 were already included as patches.
  Additional changes:
  - fix logprof/genprof to recognize "mknod" in audit.log
  - fix libapparmor python bindings to compile with python 3
  - fix wrong status message in initscript if apparmor-utils are not installed
  - parser/Makefile: fix some warnings, always respect CXX and LDFLAGS
  - fix some warnings in utils/Makefile
- remove 4 upstreamed patches
- remove mkdir /etc/apparmor.d/disable - that's done by upstream Makefile now
- update line numbers in 2 patches

OBS-URL: https://build.opensuse.org/request/show/93892
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=30
2011-11-28 11:52:47 +00:00
Stephan Kulow
6058242ab8 Accepting request 89885 from security:apparmor:factory
Two fixes for AppArmor profiles:
- make abstractions/winbind working on 64bit systems
- allow loading the libraries for samba "vfs objects" also on 32bit 
  systems (bnc#725967)

Please forward these profile fixes to openSUSE 12.1.

OBS-URL: https://build.opensuse.org/request/show/89885
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=29
2011-11-02 10:44:00 +00:00
Stephan Kulow
ec4a0f5b29 Accepting request 89465 from security:apparmor:factory
- allow loading the libraries for samba "vfs objects" (bnc#725967)

Please include this patch in 12.1

OBS-URL: https://build.opensuse.org/request/show/89465
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=28
2011-10-27 09:03:06 +00:00
Stephan Kulow
0a3dbf3200 Accepting request 88695 from security:apparmor:factory
- include autogenerated profile sniplet for samba shares (bnc#688040)
- more helpful error message for "aa-notify -p" if the user is not in
  the configured group

OBS-URL: https://build.opensuse.org/request/show/88695
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=26
2011-10-19 11:56:25 +00:00
Lars Vogdt
d96e8c3c99 Accepting request 87773 from security:apparmor:factory
- update to AppArmor 2.7.0 rc1
  - aa-notify: add --display option and warn if $DISPLAY is not set
    (important for usage with sudo on openSUSE)
  - fix syntax error on "rcapparmor stop"
  - allow read access to /proc/*/mounts in the dovecot profile

OBS-URL: https://build.opensuse.org/request/show/87773
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=25
2011-10-14 07:46:42 +00:00
Ruediger Oertel
86ade05802 Accepting request 87208 from security:apparmor:factory
- add patch with upstream changes since 2.7.0 beta2 release
  - add example parser.conf
  - print warning if profile cache directory doesn't exist
  - remove initscript for no longer existing aa-eventd (bnc#720617)
  - set correct $HOME in aa-notify
- enable caching of profiles (= massive speedup) (bnc#689458)
- add comments for patches in .spec and comments in some patches
- run spec-cleaner

- add libtool as buildrequire to make the spec file more reliable

OBS-URL: https://build.opensuse.org/request/show/87208
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=24
2011-10-10 12:10:08 +00:00
Lars Vogdt
57ed84dd83 Accepting request 82501 from security:apparmor:factory
- update to AppArmor 2.7.0 beta2
  - includes fixes for bnc#717707, bnc#678749, bnc#685674, bnc#679182,
    bnc#691072, bnc#705319, bnc#713728
- add some missing perl module Requires to perl-apparmor

OBS-URL: https://build.opensuse.org/request/show/82501
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=23
2011-09-19 20:48:33 +00:00
Sascha Peilicke
76467be0e2 Accepting request 82045 from security:apparmor:factory
- update to AppArmor 2.7.0 beta1, for details see 
  http://wiki.apparmor.net/index.php/ReleaseNotes_2_7
- removed lots of patches I pushed upstream
- disabled apparmor-2.5.1-unified-build (patch to use automake,
  does not apply to 2.7 and probably won't be accepted upstream)
- disabled build of tomcat_apparmor (doesn't build, deprecated upstream)
- run spec-cleaner
- remove *.la files
- move usr.sbin.nscd profile back to apparmor-profiles package

- Update patch apparmor-profiles-usr.sbin.dnsmasq to include
  /var/lib/libvirt/dnsmasq/*.leases (bnc#694197).

OBS-URL: https://build.opensuse.org/request/show/82045
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=22
2011-09-14 11:56:46 +00:00
Sascha Peilicke
c36abb7d55 Accepting request 81356 from security:apparmor:factory
- install SubDomain.pm compat module (bnc#713408)

- Update to 2.6.1.
  - One patch eliminated
  - Lots of minor fixes
  - Split out more common abstractions
- Add check_for_apparmor() helper.

- dhcpd: Fix apparmor profile (bnc#692428)

 
- Fixed typos in descriptions and summaries of apparmor.spec
 

- move the requires and prerequires to the right package

OBS-URL: https://build.opensuse.org/request/show/81356
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=20
2011-09-09 09:06:14 +00:00
Sascha Peilicke
4524557d11 Accepting request 77678 from security:apparmor:factory
- Add apparmor-securityfs-systemd.patch: do not mount securityfs
  when running under systemd, just access the directory, systemd
  will automount it (bnc#704460).

OBS-URL: https://build.opensuse.org/request/show/77678
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=18
2011-08-02 14:41:53 +00:00
Sascha Peilicke
187b830520 Accepting request 75398 from security:apparmor:factory
- Fixed building of pam_apparmor to properly link libpam (bnc#696553).
- Fixed building of apache2-mod_apparmor to properly link (bnc#701821). (forwarded request 74458 from jeff_mahoney)

OBS-URL: https://build.opensuse.org/request/show/75398
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=16
2011-07-05 11:45:31 +00:00
Sascha Peilicke
b5a1419370 Accepting request 65172 from security:apparmor:factory
Accepted submit request 65172 from user licensedigger

OBS-URL: https://build.opensuse.org/request/show/65172
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=14
2011-03-25 08:04:51 +00:00
Sascha Peilicke
ccb3ab3ed8 Accepting request 63720 from security:apparmor:factory
Accepted submit request 63720 from user coolo

OBS-URL: https://build.opensuse.org/request/show/63720
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=12
2011-03-10 11:49:13 +00:00
Sascha Peilicke
99c4dc988e Accepting request 62599 from security:apparmor:factory
Accepted submit request 62599 from user coolo

OBS-URL: https://build.opensuse.org/request/show/62599
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=10
2011-02-23 10:04:10 +00:00
e0e7b0c209 Accepting request 59942 from security:apparmor:factory
Accepted submit request 59942 from user jeff_mahoney

OBS-URL: https://build.opensuse.org/request/show/59942
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=7
2011-02-03 21:31:10 +00:00
Lars Vogdt
a535402f17 Accepting request 59064 from security:apparmor:factory
Accepted submit request 59064 from user jeff_mahoney

OBS-URL: https://build.opensuse.org/request/show/59064
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=5
2011-01-25 12:16:44 +00:00
cb8cbecbf9 Accepting request 58682 from security:apparmor:factory
Accepted submit request 58682 from user coolo

OBS-URL: https://build.opensuse.org/request/show/58682
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=3
2011-01-18 12:50:57 +00:00
f270973a6c Accepting request 57745 from security:apparmor:factory
Accepted submit request 57745 from user jeff_mahoney

OBS-URL: https://build.opensuse.org/request/show/57745
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/apparmor?expand=0&rev=1
2011-01-17 16:43:05 +00:00