Merge ~sergiodj/ubuntu/+source/sssd:bug1910611-update-apparmor-focal into ubuntu/+source/sssd:ubuntu/focal-devel
Status: | Merged | ||||
---|---|---|---|---|---|
Approved by: | Sergio Durigan Junior | ||||
Approved revision: | 219ccf95c2bf926f9868c5abda944d24bef7f326 | ||||
Merge reported by: | Sergio Durigan Junior | ||||
Merged at revision: | 219ccf95c2bf926f9868c5abda944d24bef7f326 | ||||
Proposed branch: | ~sergiodj/ubuntu/+source/sssd:bug1910611-update-apparmor-focal | ||||
Merge into: | ubuntu/+source/sssd:ubuntu/focal-devel | ||||
Diff against target: |
36 lines (+13/-0) 2 files modified
debian/apparmor-profile (+5/-0) debian/changelog (+8/-0) |
||||
Related bugs: |
|
Reviewer | Review Type | Date Requested | Status |
---|---|---|---|
Christian Ehrhardt (community) | Approve | ||
Canonical Server | Pending | ||
Review via email: mp+396454@code.launchpad.net |
Description of the change
This is the fix for bug 1910611 on Focal.
The sssd apparmor profile is outdated with regards to a few aspects:
- It doesn't allow the execution of binaries under /usr/libexec/sssd/*
- It doesn't allow sssd to read configuration files under /etc/sssd/conf.d/*
- It doesn't allow sssd to read files under /etc/gss/mech.d/*
The original bug only complained about the first item, but while investigating I found the other two issues, so I'm fixing them as well.
The SRU template is already in place, and contains specific instructions for reproducing the bug and testing the package.
Here's a PPA with the proposed package:
https:/
And autopkgtest is still happy:
autopkgtest [18:00:56]: @@@@@@@
ldap-user-
ldap-user-
I haven't been able to post an MP for hirsute yet because sssd doesn't compile on i386 there (there's a problem with uid-wrapper:i386 which I'm investigating). I know the SRU won't be accepted until the hirsute update is done, so even if this MP (and groovy's) is approved, I won't upload the package just yet.