Merge ~sergiodj/ubuntu/+source/sssd:bug1910611-update-apparmor-hirsute into ubuntu/+source/sssd:ubuntu/devel
Status: | Merged | ||||
---|---|---|---|---|---|
Approved by: | Sergio Durigan Junior | ||||
Approved revision: | 2c49e64e959fa2c6fcb4169d66417b4d40266b84 | ||||
Merged at revision: | 2c49e64e959fa2c6fcb4169d66417b4d40266b84 | ||||
Proposed branch: | ~sergiodj/ubuntu/+source/sssd:bug1910611-update-apparmor-hirsute | ||||
Merge into: | ubuntu/+source/sssd:ubuntu/devel | ||||
Diff against target: |
36 lines (+13/-0) 2 files modified
debian/apparmor-profile (+5/-0) debian/changelog (+8/-0) |
||||
Related bugs: |
|
Reviewer | Review Type | Date Requested | Status |
---|---|---|---|
Christian Ehrhardt (community) | Approve | ||
Canonical Server Core Reviewers | Pending | ||
Canonical Server | Pending | ||
Review via email: mp+396542@code.launchpad.net |
Description of the change
This is the fix for bug 1910611 on Hirsute.
The sssd apparmor profile is outdated with regards to a few aspects:
- It doesn't allow the execution of binaries under /usr/libexec/sssd/*
- It doesn't allow sssd to read configuration files under /etc/sssd/conf.d/*
- It doesn't allow sssd to read files under /etc/gss/mech.d/*
The original bug only complained about the first item, but while investigating I found the other two issues, so I'm fixing them as well.
Here's a PPA with the proposed package:
https:/
And autopkgtest is still happy:
autopkgtest [23:17:14]: @@@@@@@
ldap-user-
ldap-user-
I'm marking Christian as a reviewer because he also reviewed (and approved) the Focal MP.
Christian, as I said in the Focal MP:
1) There's also a Groovy MP for this: https:/ /code.launchpad .net/~sergiodj/ ubuntu/ +source/ sssd/+git/ sssd/+merge/ 396453
2) I submitted this same change to Debian here: https:/ /salsa. debian. org/sssd- team/sssd/ -/merge_ requests/ 12
Thanks!